Malware

Zusy.111920 information

Malware Removal

The Zusy.111920 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.111920 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.111920?


File Info:

name: 78CFF490AF26FD63F19E.mlw
path: /opt/CAPEv2/storage/binaries/0a6171c50dc48ecce2ee072eb1a26c8c3b2f117723cea4cd87660cec6d30ce8d
crc32: FA3EE810
md5: 78cff490af26fd63f19ea4761f0f850c
sha1: 3c349bf4808699d3d1aaa12b09e0b8ee29ca0adc
sha256: 0a6171c50dc48ecce2ee072eb1a26c8c3b2f117723cea4cd87660cec6d30ce8d
sha512: 7e36f72b1b2608c5df1a8d9cf4aa80611fc1ab7fb228002d1ce728f147471f1e72ff2496f0139fb26815c91acb94da093e42602c541a97e62446c9cdf2aebca4
ssdeep: 12288:7uQh1+mz8Eu2nL8LLmJ0RUHGahXVPR5nWFpPoSVx1MBAf:7usIEuALILmJPGa5MbBnf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16905AF52F6C280F2C525343E19AA7735EA74EA021F15CFCB9365EE2D2D32591D93323A
sha3_384: 72638fc0928b3df3ea41e629c6ac8e618be9b9667e39153f8a6ebb3143aa5ee2ece8e4480552cfb27f08650f5a6ce33b
ep_bytes: 558bec6aff68b08d4a00688c0d460064
timestamp: 2013-04-20 12:29:19

Version Info:

FileVersion: 1.3.3.7
FileDescription: 腾讯后台开钻服务端
ProductName: 刷钻协议软件
ProductVersion: 1.3.3.7
CompanyName: QQ228843415
LegalCopyright: QQ228843415 版权所有
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Zusy.111920 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lywk
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.111920
FireEyeGeneric.mg.78cff490af26fd63
SkyhighBehavesLike.Win32.Generic.ch
ALYacGen:Variant.Zusy.111920
Cylanceunsafe
ZillyaTrojan.QQPass.Win32.66841
SangforInfostealer.Win32.QQPass.Vzle
K7AntiVirusTrojan ( 005246d51 )
AlibabaTrojanPSW:Win32/QQPass.17c3de3e
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36608.Zq0@aqDXgVjb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.QQPass.NVX
CynetMalicious (score: 100)
APEXMalicious
BitDefenderGen:Variant.Zusy.111920
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.QQPass.w
EmsisoftGen:Variant.Zusy.111920 (B)
F-SecureTrojan:W32/DelfInject.R
VIPREGen:Variant.Zusy.111920
TrendMicroTROJ_GEN.R03BC0GKU23
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
VaristW32/S-9a0e6078!Eldorado
AviraTR/PSW.QQpass.fmbec
Antiy-AVLTrojan[PSW]/Win32.QQPass
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Wacatac.B!ml
XcitiumWorm.Win32.Dropper.RA@1qraug
ArcabitTrojan.Zusy.D1B530
GDataWin32.Application.PSE.1OV7PVV
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5553227
McAfeeArtemis!78CFF490AF26
MAXmalware (ai score=86)
VBA32BScope.Trojan.Downloader
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R03BC0GKU23
RisingStealer.QQPass!1.64F7 (CLASSIC)
YandexTrojan.GenAsa!AALoWdBe9qg
IkarusTrojan-PSW.QQpass
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.PHP!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.480869
DeepInstinctMALICIOUS

How to remove Zusy.111920?

Zusy.111920 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment