Malware

Zusy.Elzob.13279 removal instruction

Malware Removal

The Zusy.Elzob.13279 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.Elzob.13279 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Code injection with CreateRemoteThread in a remote process
  • Attempts to modify desktop wallpaper
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Harvests credentials from local FTP client softwares
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Zusy.Elzob.13279?


File Info:

name: 75A504CC441D7B514112.mlw
path: /opt/CAPEv2/storage/binaries/a1a41ee5040a5683fdc77db68b21f54ef5c71f5318140bff824be7f1b6a80447
crc32: 16D59510
md5: 75a504cc441d7b514112fd9ddf0167bb
sha1: cf6852760387b87912dc93d8df2681eddb2742c2
sha256: a1a41ee5040a5683fdc77db68b21f54ef5c71f5318140bff824be7f1b6a80447
sha512: 40fa15134294c2ec350cdfc65f1dbfb4adfc472bd2464a5f42e3234b89d884b24c2f5463d2f2fc84472694d379c8aff64b79b3abe9354eb2f74e2cba551b1452
ssdeep: 3072:/1Ddc2MuctxzXFKgDxavwdlZwDduV0Fsc0C9OoTsAhQ/N0jB+7:du2nctdFTxa6iDduV0vh9OWp+/Nr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CD1401263E6BEEB5E121467DA53BA7DEC00CDDF0CD4227827FC9269DE4476C4670026A
sha3_384: c8edb8b8d9f0c1349d0ba3b5c213ecd5a652849e452f542b4e442962ac97842e7ea8435314c07fc71b02d7dc5abe1771
ep_bytes: 833d4bd4420000753d8b1d4bd4420085
timestamp: 1992-06-19 19:31:05

Version Info:

0: [No Data]

Zusy.Elzob.13279 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.75a504cc441d7b51
CAT-QuickHealTrojanPWS.Zbot.Y
ALYacGen:Variant.Zusy.Elzob.13279
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.284543
SangforTrojan.Win32.Spy.Zbot
K7AntiVirusRiskware ( 0015e4f11 )
AlibabaTrojanPSW:Win32/Kryptik.a8ed2708
K7GWRiskware ( 0015e4f11 )
Cybereasonmalicious.c441d7
VirITTrojan.Win32.SMSSend.DMX
CyrenW32/DelfInject.AM.gen!Eldorado
SymantecPacked.Generic.382
ESET-NOD32a variant of Win32/Kryptik.AKSS
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Zbot-9855978-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.Elzob.13279
NANO-AntivirusTrojan.Win32.SmsSend.cbobaq
MicroWorld-eScanGen:Variant.Zusy.Elzob.13279
TencentMalware.Win32.Gencirc.114952ec
Ad-AwareGen:Variant.Zusy.Elzob.13279
EmsisoftGen:Variant.Zusy.Elzob.13279 (B)
ComodoTrojWare.Win32.Kryptik.AKFL@4r8ffy
DrWebTrojan.SMSSend.2363
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroTSPY_ZBOT.SMAR
McAfee-GW-EditionBehavesLike.Win32.ZBot.ch
SophosMal/Generic-R + Mal/EncPk-AEH
IkarusBackdoor.Hupigon
GDataGen:Variant.Zusy.Elzob.13279
JiangminTrojanSpy.Zbot.bxfk
WebrootW32.Rogue.Gen
AviraTR/Spy.Zbot.abx.8
Antiy-AVLTrojan/Generic.ASMalwS.3BBCC6
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot!CI
AhnLab-V3Spyware/Win32.Zbot.R33893
Acronissuspicious
McAfeePWS-Zbot.gen.aey
MAXmalware (ai score=99)
VBA32Malware-Cryptor.Limpopo
MalwarebytesSpyware.ZeuS
PandaTrj/Pacrypt.D
TrendMicro-HouseCallTSPY_ZBOT.SMAR
RisingSpyware.Voltar!1.AF1D (CLASSIC)
YandexTrojan.GenAsa!Pq83go0nzkg
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Zbot.EQPB!tr
BitDefenderThetaGen:NN.ZexaF.34212.myX@ayIQOugk
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.7164915.susgen

How to remove Zusy.Elzob.13279?

Zusy.Elzob.13279 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment