Malware

Zusy.123681 removal

Malware Removal

The Zusy.123681 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.123681 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Arabic
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Zusy.123681?


File Info:

name: 759697D860BE58C41DBA.mlw
path: /opt/CAPEv2/storage/binaries/3d07714bec0a26caffc06571661157a5ccdf74d7306973ca396c214da6a2265d
crc32: 3651021D
md5: 759697d860be58c41dbab5aa215be850
sha1: 00ec9e308dd7e24e33512f9fbc32626659a07215
sha256: 3d07714bec0a26caffc06571661157a5ccdf74d7306973ca396c214da6a2265d
sha512: 8d7f6a4ace7de17bcc151a736e204cad8da70129998ad73bab0fbe733adabcc5f25ce27a3d6f9105748c92379a905428ad942f34819ef0c1f7db6444bbee94e1
ssdeep: 12288:KxrEMhTP1oqN3OWy3onNCGgLXGHnxXi9sZ:KxrNhThglCi98
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T152B40183FF0387A6D1E919F5569F4E4C5F282AC442151D5353EF8C9B639ABB2302B788
sha3_384: 33cdf3ca71ccf755394319bbb8124637c026a2a88a595e2cefe9a3948123cf1b6b879eefec70135fa5e920f3aeab57e3
ep_bytes: 558bec81ecbc0000008b0d50e0420089
timestamp: 2011-10-18 11:48:47

Version Info:

InternalName: lbadole.exe
ProductVersion: 5.29.23402.54907
CompanyName: Erdoaem Corniratu
OriginalFilename: lbadole.exe
FileDescription: Erdoaem Vire Studaa 2021
FileVersion: 5.29.23402.54907
ProductName: Erdoaem
Translation: 0x0409 0x04b0

Zusy.123681 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.123681
FireEyeGeneric.mg.759697d860be58c4
McAfeeTrojan-FFFI!759697D860BE
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.173822
SangforTrojan.Win32.Agent.nil
K7AntiVirusTrojan ( 0055dd191 )
AlibabaTrojanPSW:Win32/Kryptik.c6aeb2ba
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.860be5
BaiduWin32.Trojan.Kryptik.je
VirITTrojan.Win32.X-Cryptor.LE
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.CWAO
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-62197
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.123681
NANO-AntivirusTrojan.Win32.ZbotCitadelTargeted.dmvytz
SUPERAntiSpywareTrojan.Agent/Gen-Falcomp
AvastWin32:Agent-AUYE [Trj]
TencentMalware.Win32.Gencirc.10b2e39b
Ad-AwareGen:Variant.Zusy.123681
TACHYONTrojan-Spy/W32.ZBot.519317
EmsisoftGen:Variant.Zusy.123681 (B)
ComodoTrojWare.Win32.PWS.Zbot.UWV@5ku4b1
DrWebTrojan.Siggen6.15132
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_ZCLICK.SMA
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
SophosML/PE-A + Troj/Zbot-JMK
IkarusTrojan.Win32.Crypt
GDataGen:Variant.Zusy.123681
JiangminTrojan/Yakes.qnt
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.DE4467
KingsoftWin32.Heur.KVMH008.a.(kcloud)
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.ZBot.R132528
BitDefenderThetaGen:NN.ZexaF.34212.Fy1@aWQn4AAG
ALYacGen:Variant.Zusy.123681
MAXmalware (ai score=100)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTSPY_ZCLICK.SMA
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojanSpy.Zbot!c1ocMN1H7JA
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.DSCV!tr
AVGWin32:Agent-AUYE [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Zusy.123681?

Zusy.123681 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment