Malware

Zusy.258523 removal guide

Malware Removal

The Zusy.258523 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.258523 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Creates a hidden or system file

How to determine Zusy.258523?


File Info:

crc32: D2F2F529
md5: 88f3169f56f99f23af55ec9c0c05f583
name: 88F3169F56F99F23AF55EC9C0C05F583.mlw
sha1: 4174b35d27eb0f22b3a260ebfe29bb394dc8f568
sha256: 5ed5fcd077c4bed793c75d4a27d67fabfd8b8fd856a90fc1f4f9af4805722d33
sha512: b1dcbd198f04cf0eb1fa8fc6cc09919cc3bf1d84aa40e71dc3d87598468a0b18722dd09b37095a3a9870d67c9c5002bcbbafa92b8840475959d3347e5b0fe404
ssdeep: 768:MwycuSDotX4UnzlKs0C6gHxM7SC1jwpds3acC15p22Ti:yUo7RFm7tjAds3m5ps
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright xc2xa92016 Telerik
InternalName: Fiddler.exe
FileVersion: 4.6.2.3
CompanyName: Telerik
LegalTrademarks: Fiddlerxe2x201exa2
ProductName: Fiddler
ProductVersion: 4.6.2.3
FileDescription: Fiddler
OriginalFilename: Fiddler.exe
Translation: 0x0409 0x04b0

Zusy.258523 also known as:

LionicTrojan.Win32.Generic.m!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader26.55265
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.258523
CylanceUnsafe
ZillyaTrojan.Agent.Win32.904827
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
Cybereasonmalicious.f56f99
CyrenW32/Zusy.CX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.AZM
APEXMalicious
AvastWin32:RATX-gen [Trj]
ClamAVWin.Dropper.LimeRAT-9776087-0
KasperskyHEUR:Backdoor.Win32.Generic
BitDefenderGen:Variant.Zusy.258523
NANO-AntivirusTrojan.Win32.Zusy.fesjgz
MicroWorld-eScanGen:Variant.Zusy.258523
TencentWin32.Backdoor.Generic.Eehn
Ad-AwareGen:Variant.Zusy.258523
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34236.dq0@aGhap4hi
McAfee-GW-EditionGenericRXDU-PY!88F3169F56F9
FireEyeGeneric.mg.88f3169f56f99f23
EmsisoftGen:Variant.Zusy.258523 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
eGambitTrojan.Generic
Antiy-AVLTrojan/Generic.ASMalwS.26CE4B6
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataGen:Variant.Zusy.258523
AhnLab-V3Trojan/Win32.RL_Agent.R283459
Acronissuspicious
McAfeeGenericRXDU-PY!88F3169F56F9
MAXmalware (ai score=98)
MalwarebytesBackdoor.RevengeRAT
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.100 (RDML:LLgDGZ+LAQjsArPLLcXsUw)
IkarusTrojan.MSIL.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.AZM!tr
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml

How to remove Zusy.258523?

Zusy.258523 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment