Malware

Zusy.386275 (B) information

Malware Removal

The Zusy.386275 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.386275 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Deletes its original binary from disk
  • Likely virus infection of existing system binary

How to determine Zusy.386275 (B)?


File Info:

name: 87B3E8D302F7594C9E66.mlw
path: /opt/CAPEv2/storage/binaries/5cd0816a03dd95d00cc8219d1218b11289a0aa6186bcf1bfa6845ec706dfe62d
crc32: 4A8E36BA
md5: 87b3e8d302f7594c9e662802e36e0104
sha1: e8aafe31eb0bd68a065dfc4aef2719c3a4e5c732
sha256: 5cd0816a03dd95d00cc8219d1218b11289a0aa6186bcf1bfa6845ec706dfe62d
sha512: f8d12390637a905b6209c9207e1d252f7445a816c374891ca2b98106cee5bdb8a3182f83ad6eb5d2b38a07bfa2d91c454fbe52dc6fc5fb8296e1072b32d03d97
ssdeep: 12288:ECGD7ezCllrldTRzZ1HFgVAxXxeq71d31pvY:ECuiCxdTv1HFgVAxXxeq71h12
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19C355F8E5A14047FE5603571809E7BA602542DFD2EA3D766FA1CB643FB323C6903763A
sha3_384: b93f298661c4935c51c1ca0f73d4afd46279b8bce6e09e353d14498b23419a72c3210399882ac693960f9086e1c8cd9c
ep_bytes: 558bec6aff68d0c14000685080400064
timestamp: 2011-03-26 05:35:14

Version Info:

0: [No Data]

Zusy.386275 (B) also known as:

MicroWorld-eScanGen:Variant.Zusy.386275
FireEyeGeneric.mg.87b3e8d302f7594c
ALYacGen:Variant.Zusy.386275
CylanceUnsafe
ZillyaTrojan.Agent.Win32.233308
K7AntiVirusSpyware ( 0055e3db1 )
K7GWSpyware ( 0055e3db1 )
CyrenW32/Agent.CHY.gen!Eldorado
ESET-NOD32a variant of Win32/Spy.Agent.OPC
APEXMalicious
ClamAVWin.Trojan.6601069-1
KasperskyTrojan-Spy.Win32.Agent.jxrh
BitDefenderGen:Variant.Zusy.386275
NANO-AntivirusTrojan.Win32.TrjGen.boescz
AvastWin32:Malware-gen
RisingMalware.Heuristic!ET#96% (RDMK:cmRtazrC6txnB1cYEiPwALdHYSDd)
Ad-AwareGen:Variant.Zusy.386275
DrWebTrojan.PWS.Bonque.44
EmsisoftGen:Variant.Zusy.386275 (B)
GDataGen:Variant.Zusy.386275
JiangminTrojan.Generic.aroj
AviraHEUR/AGEN.1107121
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.710072
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
McAfeeGenericRXAA-AA!87B3E8D302F7
VBA32Backdoor.MSIL.IRCBot
MalwarebytesMalware.AI.1668748915
TencentMalware.Win32.Gencirc.10b28485
YandexTrojan.GenAsa!XR2/quIb0Jw
eGambitUnsafe.AI_Score_99%
FortinetW32/Generic.AC.22793F
BitDefenderThetaGen:NN.ZexaF.34294.erW@a8@trknO
AVGWin32:Malware-gen
Cybereasonmalicious.302f75
MaxSecureTrojan.Malware.300983.susgen

How to remove Zusy.386275 (B)?

Zusy.386275 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment