Malware

Zusy.380748 (B) (file analysis)

Malware Removal

The Zusy.380748 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.380748 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid

How to determine Zusy.380748 (B)?


File Info:

name: D232A1B660AD2B6FBDD7.mlw
path: /opt/CAPEv2/storage/binaries/f632d514a7febedb1d49f4a8f2b300eaffc0da0dec8b28e4e411f6cb9fc88110
crc32: 3F1D3C75
md5: d232a1b660ad2b6fbdd72f829047f918
sha1: e8106388ed8ec516f5f816a918be00bb595f8751
sha256: f632d514a7febedb1d49f4a8f2b300eaffc0da0dec8b28e4e411f6cb9fc88110
sha512: f4e8029bf1384fbe639ef3e661711271be85390c2680e82981ca9737c2ce13d2ed798020c42832bd4c23b492e77f11fb8511b8e8493118a8af797186b98d1d43
ssdeep: 6144:NxliBoxby3WlK6la286EjFp79u2WCJiWuBqXOoAO4R8EmMHC:NxlIoxWGlzaD69WuBq1i6MHC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F4548D0034928036D87305764CFF9B798A3CBC11076559FBB3D46B7E8F756D2AA31A2A
sha3_384: 5c3a54c7e1318773b603f1c926430bf62471256371b4a2fbb47b9855e836260f3a57bbf8a2f740bd9b144e8c28246096
ep_bytes: e8c6060000e974feffff558beceb0dff
timestamp: 2020-03-29 00:53:21

Version Info:

CompanyName: GBE cOmp
FileDescription: Intellectual privacy
FileVersion: 1.0.0.1
InternalName: STUB.exe
LegalCopyright: Copyright (C) 2020
OriginalFilename: STUB.exe
ProductName: IE-p
ProductVersion: 1.0.0.1
Translation: 0x0419 0x04b0

Zusy.380748 (B) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.d232a1b660ad2b6f
McAfeeGenericRXLK-XL!D232A1B660AD
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00565d3b1 )
K7GWTrojan ( 00565d3b1 )
CyrenW32/Injector.AKT.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.ENSH
APEXMalicious
ClamAVWin.Malware.Ulises-9787519-0
KasperskyVHO:Trojan-Dropper.Win32.Injector.gen
BitDefenderGen:Variant.Zusy.380748
NANO-AntivirusTrojan.Win32.Morphine.hjsaoo
MicroWorld-eScanGen:Variant.Zusy.380748
AvastWin32:PWSX-gen [Trj]
Ad-AwareGen:Variant.Zusy.380748
DrWebBackDoor.Morphine.1
McAfee-GW-EditionGenericRXLK-XL!D232A1B660AD
EmsisoftGen:Variant.Zusy.380748 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.380748
JiangminTrojan.Inject.bdiy
AviraHEUR/AGEN.1138134
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.3352889
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Malware/Win32.Generic.C4069010
BitDefenderThetaGen:NN.ZexaF.34084.ru0@aWGYzylk
ALYacGen:Variant.Zusy.380748
VBA32Trojan.Convagent
MalwarebytesTrojan.Injector
RisingTrojan.Generic@ML.95 (RDML:sSa/PoxOpkErtFemZoWoEA)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.82199810.susgen
FortinetW32/Ulises.AA6F!tr
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.660ad2

How to remove Zusy.380748 (B)?

Zusy.380748 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment