Malware

Zusy.384756 removal tips

Malware Removal

The Zusy.384756 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.384756 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Zusy.384756?


File Info:

name: B7423D2B6745DCCBAC7D.mlw
path: /opt/CAPEv2/storage/binaries/d7f0d802b1bf1fc52b7d2153bfa1d1e34a97f4fcf6ad9ede2eabcefca29e36cc
crc32: F32938B1
md5: b7423d2b6745dccbac7d11ebcd986102
sha1: a733a1460df389de9898edd64ed0c655e995f0d6
sha256: d7f0d802b1bf1fc52b7d2153bfa1d1e34a97f4fcf6ad9ede2eabcefca29e36cc
sha512: 3814599c1d665f33679f07ef661bb96a7e97c4321f57e2ef8c2a6776e5ab96f798074a428b536b2188c4657a0bcc4bf0158ec065aa5a18b31080435cdf4442d3
ssdeep: 3072:WKdNXF3m6meZxNeCuZsjsKgxmZcXHvEuR5yScKp:WQL3m6meZreCuZsdc3vMSVp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CF3429113680C076E31A173449D6E6F06AAAAC384BA4A28FF7B47F795E311D3593B14F
sha3_384: 7dafee7e98d2aa9d2da9812437475453dd4c7111a70718b382865f55d60b786aa5736e0a950b3afb35d5efc92ae68e12
ep_bytes: e862670000e978feffff8bff558bec51
timestamp: 2018-09-13 07:14:06

Version Info:

0: [No Data]

Zusy.384756 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Farfli.m!c
MicroWorld-eScanGen:Variant.Zusy.384756
FireEyeGeneric.mg.b7423d2b6745dccb
McAfeeGenericRXQD-ZB!B7423D2B6745
CylanceUnsafe
SangforTrojan.Win32.Agent.V3yl
K7AntiVirusTrojan ( 001f30661 )
AlibabaBackdoor:Win32/Farfli.20e86611
K7GWTrojan ( 001f30661 )
Cybereasonmalicious.b6745d
CyrenW32/ABRisk.YUNS-0782
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.UDQ
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.Win32.Farfli.gen
BitDefenderGen:Variant.Zusy.384756
NANO-AntivirusTrojan.Win32.Jaiko.hrqgyv
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10cf8c1e
Ad-AwareGen:Variant.Zusy.384756
EmsisoftGen:Variant.Zusy.384756 (B)
DrWebTrojan.Siggen8.53276
ZillyaTrojan.Agent.Win32.1310042
TrendMicroTROJ_GEN.R002C0PFQ22
McAfee-GW-EditionBehavesLike.Win32.NetLoader.dm
SophosMal/Generic-S
GDataGen:Variant.Zusy.384756
JiangminBackdoor.Farfli.fnh
AviraHEUR/AGEN.1242839
ArcabitTrojan.Zusy.D5DEF4
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4511923
VBA32BScope.Backdoor.Peep
ALYacGen:Variant.Zusy.384756
MAXmalware (ai score=87)
MalwarebytesDDoSTool.Nitol
TrendMicro-HouseCallTROJ_GEN.R002C0PFQ22
RisingTrojan.Generic@AI.80 (RDMK:2LSlGno+3BSwJmQXoT+Uxg)
YandexTrojan.Agent!BvUyg3U7mXI
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.34742.puW@aqd@OYdj
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Zusy.384756?

Zusy.384756 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment