Malware

Zusy.369012 (B) removal instruction

Malware Removal

The Zusy.369012 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.369012 (B) virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Zusy.369012 (B)?


File Info:

name: 15E315E1E46DE32EC6B5.mlw
path: /opt/CAPEv2/storage/binaries/baed9679cf43f705cd6fde6fc05522fcf9ea6275a6229727b5ea6932944cf534
crc32: 426ED444
md5: 15e315e1e46de32ec6b533b8ab72e79b
sha1: b6de172bbba5be6bd5aecaafcbe58316de118a73
sha256: baed9679cf43f705cd6fde6fc05522fcf9ea6275a6229727b5ea6932944cf534
sha512: 7dd32ed7bef2aba8892c7d85c96959aba82b1a6cb36072d649e9788708bf982c9d90c219e86e561fb620cb9fcab038c8eadb13301a5c163f044c5a39f481481f
ssdeep: 3072:uoQyEiE8D7Ijw7f9tpFeIy8jnC8qXnD5ACl9Mn9v23k0Yk+4O2kD1QGyWSEhN:fPvjeIy8jMnlq9eHYk+5JQjWSE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T170042815B6F5F068D5A205F23A3CF1955534BDB18B35A09B39C22B0E09346D9CE72FA3
sha3_384: 7e66bfb38ba6701f6e6daf26dd39018c0a3cf053b521044d1179bd97ec834a0c722f5af4ae0f2455c24bbf54ef48f142
ep_bytes: e85a050000e944feffffccccccccccff
timestamp: 2016-02-26 00:13:55

Version Info:

Translation: 0x0409 0x04b0

Zusy.369012 (B) also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.369012
FireEyeGeneric.mg.15e315e1e46de32e
McAfeeGenericRXND-GN!15E315E1E46D
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/MSIL_Kryptik.CZX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HHDP
APEXMalicious
KasperskyHEUR:Backdoor.Win32.Mokes.vho
BitDefenderGen:Variant.Zusy.369012
AvastWin32:Trojan-gen
Ad-AwareGen:Variant.Zusy.369012
EmsisoftGen:Variant.Zusy.369012 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SophosMal/Generic-S
GDataGen:Variant.Zusy.369012
AviraTR/Crypt.XPACK.Gen3
Antiy-AVLTrojan/Generic.ASMalwS.31069FC
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R450804
BitDefenderThetaGen:NN.ZexaF.34062.lu0@a8F4cGai
ALYacGen:Variant.Zusy.369012
MAXmalware (ai score=85)
VBA32BScope.Backdoor.Mokes
MalwarebytesTrojan.SmokeLoader
RisingTrojan.Injector!1.D328 (CLASSIC)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.ACGU!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.1e46de
PandaTrj/Genetic.gen

How to remove Zusy.369012 (B)?

Zusy.369012 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment