Malware

Zusy.377320 (B) malicious file

Malware Removal

The Zusy.377320 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.377320 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Performs a large number of encryption calls using the same key possibly indicative of ransomware file encryption behavior

How to determine Zusy.377320 (B)?


File Info:

name: 54BCA575FEA97CF9CB4B.mlw
path: /opt/CAPEv2/storage/binaries/1a65d3ff7a52788323ae0a1385fd4fbf24ad6eeddd4a429b1ed326720dc826ed
crc32: F4C811D0
md5: 54bca575fea97cf9cb4be0df5f956c54
sha1: ecb42bd8fc5fcacfb3af8d71f540d8d2e4ec8251
sha256: 1a65d3ff7a52788323ae0a1385fd4fbf24ad6eeddd4a429b1ed326720dc826ed
sha512: 88c0bb9d45958f039153bb9601bf8e0a22fcb725c3685204a0061552e410e5b2648720823719649fa296a844dbf784b38e46e6b94762b1604e65c4a69d69e184
ssdeep: 24576:2XU09t8XLX8hf6VAYCG6WouT8watr4aO5u:2EutzfsCG5h9aR4e
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T154359F02F781C062FEDB99334A5AF231967C791E4037952F13981E79B9B2271163EE63
sha3_384: 7c97fd7b53aa4a9325e1eaa17992e2887f10988e7990bcd1ea6dad88b44e5159fc3d0223df8299c27b1e82caad99e6bc
ep_bytes: e86e050000e97afeffff558bec56ff75
timestamp: 2021-05-28 09:25:39

Version Info:

FileVersion: 2.0.3.1312
Comments: CopyLick Corporation
FileDescription: CopyLick
ProductVersion: 2.03.1312
LegalCopyright: (C) CopyLick. All rights reserved.
CompanyName: CopyLick? System
ProductName: CopyLick
Translation: 0x0804 0x04b0

Zusy.377320 (B) also known as:

LionicTrojan.Win32.Zusy.4!c
MicroWorld-eScanGen:Variant.Zusy.377320
FireEyeGen:Variant.Zusy.377320
McAfeeArtemis!54BCA575FEA9
CylanceUnsafe
ZillyaTrojan.Obfuscated.Win32.95080
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/GenCBL.2b3f780b
K7GWTrojan ( 00579ffd1 )
K7AntiVirusTrojan ( 00579ffd1 )
CyrenW32/AutoIt.UO.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenCBL.AJQ
Paloaltogeneric.ml
ClamAVWin.Malware.Nymeria-9879923-0
BitDefenderGen:Variant.Zusy.377320
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.11cc9f1b
EmsisoftGen:Variant.Zusy.377320 (B)
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DB222
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan.Win32.Generic
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1144388
Antiy-AVLTrojan/Generic.ASMalwS.30F6B20
MicrosoftTrojan:Win32/Sabsik.DA!MTB
GDataGen:Variant.Zusy.377320
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R416907
VBA32Trojan.Script
ALYacGen:Variant.Zusy.377320
MAXmalware (ai score=85)
MalwarebytesTrojan.Dropper
TrendMicro-HouseCallTROJ_GEN.R002C0DB222
RisingAdware.Agent!1.D343 (CLASSIC)
MaxSecureTrojan.Malware.117045383.susgen
FortinetW32/GenCBL.AJQ!tr
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen

How to remove Zusy.377320 (B)?

Zusy.377320 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment