Malware

Application.Zusy.403022 information

Malware Removal

The Application.Zusy.403022 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Zusy.403022 virus can do?

  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Application.Zusy.403022?


File Info:

name: CE76304472A1A02ED07D.mlw
path: /opt/CAPEv2/storage/binaries/eac9bf6352e9b98d1742284d4d0c381a03df00f60206a28b100db394a70d5b9f
crc32: A5CD3322
md5: ce76304472a1a02ed07d5b80aa754bc9
sha1: 480abf6b3066861ab3cf985bc24066ee7f79a721
sha256: eac9bf6352e9b98d1742284d4d0c381a03df00f60206a28b100db394a70d5b9f
sha512: 268cf2a532c02d1944daa6724dfdacbf7b1e9507ae4e108bf725bcb0e8635ed65eb78951a2e3fb96b181c8616fe4f7f117ecdc3b5eafe9c0f681e567e094a3e2
ssdeep: 98304:OOGuvUwnnUx8Pn7TTtsnXTHrFufIjH4cQy7d4H2xBe2LUsh:O0Ux8PnZsXrrIgjH4c5uun
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1E74623B311551141D1F4C83BC93F7DD6B1F5026A4A82ECBC66AABDC22932DF5E30698B
sha3_384: b392bdb09c201572dcae463b2f8fb92c9bff75fe4288e6101d464df641d60dd3a02faf191bb7718f13f93ef6305c2b50
ep_bytes: 6831a6b8dbe8ecda51004ae98e952e00
timestamp: 2021-11-12 06:25:49

Version Info:

0: [No Data]

Application.Zusy.403022 also known as:

LionicRiskware.Win32.Gamech.1!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Application.Zusy.403022
FireEyeGeneric.mg.ce76304472a1a02e
ALYacGen:Variant.Application.Zusy.403022
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 7000001c1 )
AlibabaRiskWare:Win32/Gamech.7aa8f6fd
K7GWTrojan ( 7000001c1 )
Cybereasonmalicious.b30668
CyrenW32/Agent.DPT.gen!Eldorado
Elasticmalicious (high confidence)
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Vmprotbad-9867392-0
Kasperskynot-a-virus:HEUR:RiskTool.Win32.Gamech.vho
BitDefenderGen:Variant.Application.Zusy.403022
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Application.Zusy.403022
TACHYONTrojan/W32.Agent.5505536.D
SophosMal/Generic-R + Mal/VMProtBad-A
ZillyaTrojan.VMProtect.Win32.57001
TrendMicroTROJ_GEN.R002C0PDL22
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Application.Zusy.403022 (B)
SentinelOneStatic AI – Malicious PE
JiangminRiskTool.Gamech.gy
AviraHEUR/AGEN.1200237
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Application.Zusy.403022
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.AGEN.C4482320
Acronissuspicious
McAfeeGenericRXRG-EU!CE76304472A1
MAXmalware (ai score=76)
MalwarebytesTrojan.MalPack.VMP
TrendMicro-HouseCallTROJ_GEN.R002C0PDL22
RisingTrojan.Generic@AI.96 (RDMK:mAgyYsB6OOnV1cbX5nqj4g)
YandexRiskware.VMProtect!lCEybIibk2o
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.103643099.susgen
FortinetW32/Agent.ADER!tr
BitDefenderThetaGen:NN.ZexaF.34742.@FW@a0Oofoli
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Application.Zusy.403022?

Application.Zusy.403022 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment