Malware

Should I remove “Zusy.369012”?

Malware Removal

The Zusy.369012 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.369012 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Zusy.369012?


File Info:

crc32: 1FD0DCE4
md5: ee3c6827bdc5d0c06fbe03ebe35d1ca4
name: EE3C6827BDC5D0C06FBE03EBE35D1CA4.mlw
sha1: 05f6a88dcc9a32903fbdbcb7e8abb0df5e1e4e87
sha256: b82a8d51ff671aa2c53065a16aebe00b4f4365dd58b933d047bf4fcbb453376f
sha512: c065f0a389ccda5d62ac31bbda4767be6ef644594da5bf3cf42f3751f4884923c9479fe6b9e0f5ef510485edd3a6c07dcb39f88581cb5173825c310b3db43d21
ssdeep: 3072:nSOuRU7IgTLRSxrNpFeIYj9/nYBj5Y/oy4ghv23k0YCoqmAOI07LqZeV8ug:NutxJjeI0nYs/oy4gheHYCnOXqZeV8u
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0

Zusy.369012 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.369012
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
Cybereasonmalicious.7bdc5d
CyrenW32/MSIL_Kryptik.CZX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HHHH
APEXMalicious
AvastWin32:Trojan-gen
KasperskyBackdoor.Win32.Mokes.anqu
BitDefenderGen:Variant.Zusy.369012
MicroWorld-eScanGen:Variant.Zusy.369012
Ad-AwareGen:Variant.Zusy.369012
SophosMal/Generic-S
BitDefenderThetaAI:Packer.136A1EFD1F
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.ee3c6827bdc5d0c0
EmsisoftGen:Variant.Zusy.369012 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen3
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Zusy.369012
AhnLab-V3Malware/Win32.Generic.C4224968
McAfeeGenericRXNP-ZO!EE3C6827BDC5
MAXmalware (ai score=83)
VBA32BScope.Backdoor.Mokes
MalwarebytesTrojan.SmokeLoader
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.D2DE (CLASSIC)
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.ACGU!tr
AVGWin32:Trojan-gen

How to remove Zusy.369012?

Zusy.369012 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment