Malware

Zusy.320925 (B) removal guide

Malware Removal

The Zusy.320925 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.320925 (B) virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Zusy.320925 (B)?


File Info:

crc32: 4C89F7D7
md5: cb84d4b4400e6c6aa11bde2bba6f5e47
name: CB84D4B4400E6C6AA11BDE2BBA6F5E47.mlw
sha1: 376c901e91b54df0eee47c90077b97d86641677f
sha256: 1cd2bcd481bc78ccacff4dec933f920702b40bb3537c41513820b651b4606fc0
sha512: d7f298f582dc08afa740cd14f4b75809872ed243b87a534761c23ff86c66febcb8d7ee7d55c135ee341336036c05b58404900a0fef93823e84650f6b8a96f21b
ssdeep: 384:Fi7xHOSmacWsKkh+514VxihV4zervlMGmsrCzHfUk8DQy7kQ81AHv:FKxHOS33fkcoVxa40NMirCeQwk7s
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright ? 1996-2010 Adobe, Inc.
InternalName: Adobe? Flash? Player Installer/Uninstaller 10.1
FileVersion: 10,1,53,64
CompanyName: Adobe Systems, Inc.
LegalTrademarks: Adobe? Flash? Player
ProductName: Flash? Player Installer/Uninstaller
ProductVersion: 10,1,53,64
FileDescription: Adobe? Flash? Player Installer/Uninstaller 10.1 r53
OriginalFilename: FlashUtil.exe
Translation: 0x0409 0x04b0

Zusy.320925 (B) also known as:

BkavW32.InNhcA.Worm
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader6.7800
MicroWorld-eScanGen:Variant.Zusy.320925
FireEyeGeneric.mg.cb84d4b4400e6c6a
CAT-QuickHealBackdoor.Simbot.G4
McAfeeBackDoor-EYG
CylanceUnsafe
ZillyaTrojan.InjectGen.Win32.5
AegisLabTrojan.Win32.Inject.lJhA
SangforMalware
K7AntiVirusTrojan ( 001f574c1 )
BitDefenderGen:Variant.Zusy.320925
K7GWTrojan ( 001fbdf71 )
Cybereasonmalicious.4400e6
BitDefenderThetaAI:Packer.4CE631F61F
CyrenW32/A-493428c6!Eldorado
SymantecTrojan Horse
TrendMicro-HouseCallTROJ_KRYPTK.SMS
AvastWin32:Taidoor-D [Trj]
ClamAVWin.Trojan.Injector-6297684-0
KasperskyTrojan.Win32.Inject.azgw
AlibabaTrojan:Win32/Dorv.8d7d5720
NANO-AntivirusTrojan.Win32.Inject.dwskba
ViRobotBackdoor.Win32.Simbot.27136
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
Ad-AwareGen:Variant.Zusy.320925
SophosML/PE-A + Troj/Simbot-J
ComodoTrojWare.Win32.Inject.ka@4o81ww
F-SecureTrojan.TR/Crypt.ZPACK.Gen
BaiduWin32.Trojan.Inject.bf
VIPRETrojan.Win32.Inject.cj (v)
TrendMicroTROJ_KRYPTK.SMS
McAfee-GW-EditionBehavesLike.Win32.Backdoor.mh
EmsisoftGen:Variant.Zusy.320925 (B)
SentinelOneStatic AI – Malicious PE – Spyware
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan/Win32.Inject.azgw
KingsoftWin32.Troj.Inject.az.(kcloud)
MicrosoftTrojan:Win32/Dorv.A
ArcabitTrojan.Zusy.D4E59D
SUPERAntiSpywareTrojan.Agent/Gen-Kazy
ZoneAlarmTrojan.Win32.Inject.azgw
GDataGen:Variant.Zusy.320925
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.CSon.R7666
Acronissuspicious
VBA32SScope.Backdoor.Simbot
ALYacGen:Variant.Zusy.320925
MAXmalware (ai score=80)
MalwarebytesSimbot.Backdoor.Stealer.DDS
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of Win32/Injector.ELH
TencentTrojan.Win32.Inject.bbyoa
YandexTrojan.GenAsa!0BbFmfh8pGM
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.1613479.susgen
FortinetW32/Injector.ELH!tr
AVGWin32:Taidoor-D [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.d1c

How to remove Zusy.320925 (B)?

Zusy.320925 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment