Malware

Mal/Zusy-A malicious file

Malware Removal

The Mal/Zusy-A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Zusy-A virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup

How to determine Mal/Zusy-A?


File Info:

name: 1C0D9A9E9421B6A9A736.mlw
path: /opt/CAPEv2/storage/binaries/f642ef5a39d28d5dd623af516d84ff5bca84813dbce227957951101bbc93e8ac
crc32: EEEB0D81
md5: 1c0d9a9e9421b6a9a736efe0460d5dac
sha1: a3ec5a473a7c3cb9c8f72224e831fe589a1309eb
sha256: f642ef5a39d28d5dd623af516d84ff5bca84813dbce227957951101bbc93e8ac
sha512: 5463cc65fa5b6c5a1eef1a2f6bbeb82fe3af1abe09dbb5a57321e1cfe6021d82c09983485d12334fd28c38923ea354eb170d4b0c328db9180d4ea601ba2a4c78
ssdeep: 6144:SNy6C9RpRpEGgXlAbehLQq2UM7Je4kv0HO883Si5/0y:PEGgnhLR2UM7A4S0S3S0/0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T145A47D10F662D035F0E302F68EBA82F4A9347A70077984C777D469AE6B686E4ED35713
sha3_384: 7b2bca65a18fd113ded70d7fef8f0ab1d85793b0be19617d9dc3c5f131860147cdfcffc231f838679883bd0b6e08c2ca
ep_bytes: 558bece8d82a0100e8030000005dc3cc
timestamp: 2014-06-16 11:09:27

Version Info:

0: [No Data]

Mal/Zusy-A also known as:

Elasticmalicious (high confidence)
DrWebTrojan.KillFiles.14550
MicroWorld-eScanGen:Variant.Backdoor.ShadowWali.1
FireEyeGeneric.mg.1c0d9a9e9421b6a9
ALYacGen:Variant.Backdoor.ShadowWali.1
MalwarebytesWorm.Agent
ZillyaWorm.Agent.Win32.28025
K7AntiVirusTrojan ( 00023ea01 )
K7GWTrojan ( 00023ea01 )
Cybereasonmalicious.e9421b
BitDefenderThetaAI:Packer.0585414E1F
VirITTrojan.Win32.Agent4.BXTR
CyrenW32/S-4112289e!Eldorado
SymantecTrojan.Tinba
ESET-NOD32Win32/Agent.NPZ
APEXMalicious
AvastWin32:Malware-gen
BitDefenderGen:Variant.Backdoor.ShadowWali.1
NANO-AntivirusTrojan.Win32.KillFiles.didhhl
TencentMalware.Win32.Gencirc.11e3bae9
EmsisoftGen:Variant.Backdoor.ShadowWali.1 (B)
ComodoWorm.Win32.Rikihaki.A@5sbndo
BaiduWin32.Worm.Agent.fw
TrendMicroWORM_RIKIHAKI.SM
McAfee-GW-EditionBehavesLike.Win32.CoinMiner.gh
SophosMal/Zusy-A
AviraHEUR/AGEN.1119489
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftWorm:Win32/Rikihaki.A
GDataGen:Variant.Backdoor.ShadowWali.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R148972
McAfeeW32/Worm-FYO!1C0D9A9E9421
VBA32BScope.Trojan.KillFiles
CylanceUnsafe
TrendMicro-HouseCallWORM_RIKIHAKI.SM
RisingWorm.Rikihaki!1.A2F0 (RDMK:cmRtazoGft/pxGxnLZDFNUfRmQen)
YandexWorm.Agent!cazTjFK00UQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.NQD!worm
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Mal/Zusy-A?

Mal/Zusy-A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment