Malware

Zusy.320925 removal instruction

Malware Removal

The Zusy.320925 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.320925 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Zusy.320925?


File Info:

crc32: CE1EBD09
md5: 4043961c1a05125fa1b1abee622a2c1c
name: 4043961C1A05125FA1B1ABEE622A2C1C.mlw
sha1: afdd53b430b9018d503b173f5d469c66a9fa64e9
sha256: dd260a946f507fcd91e77ea4a4a188073e6928343a19a6629ab34cd480f5a62f
sha512: ae4b8f67ba493db8215b6e53242ddacbd0b427c81e72e7fb43d509f6dfeac888cdc3b46254914c2f90711bc52571eda0b8cb39e54e0a4999a8bb7fcd87f0afef
ssdeep: 384:R0rsW1gHZ4++srB9V2QToG6FSM4ougjOJBmS+FGUwQybPp1FHZ:R0sW1gH0sb9oGdtLgewfGUwQI3f
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright ? 1996-2010 Adobe, Inc.
InternalName: Adobe? Flash? Player Installer/Uninstaller 10.1
FileVersion: 10,1,53,64
CompanyName: Adobe Systems, Inc.
LegalTrademarks: Adobe? Flash? Player
ProductName: Flash? Player Installer/Uninstaller
ProductVersion: 10,1,53,64
FileDescription: Adobe? Flash? Player Installer/Uninstaller 10.1 r53
OriginalFilename: FlashUtil.exe
Translation: 0x0409 0x04b0

Zusy.320925 also known as:

BkavW32.InNhcA.Worm
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.320925
FireEyeGeneric.mg.4043961c1a05125f
CAT-QuickHealBackdoor.Simbot.G4
ALYacGen:Variant.Zusy.320925
CylanceUnsafe
VIPRETrojan.Win32.Inject.cj (v)
AegisLabTrojan.Win32.Inject.lJhA
SangforMalware
K7AntiVirusTrojan ( 002331771 )
BitDefenderGen:Variant.Zusy.320925
K7GWTrojan ( 001fbdf71 )
Cybereasonmalicious.c1a051
BaiduWin32.Trojan.Inject.bf
CyrenW32/Injector.AV.gen!Eldorado
SymantecTrojan.Dropper
APEXMalicious
AvastWin32:Taidoor-D [Trj]
ClamAVWin.Trojan.Inject-132
KasperskyTrojan.Win32.Inject.bbyo
NANO-AntivirusTrojan.Win32.Inject.csnmkc
ViRobotTrojan.Win32.Cson.Gen.A
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
Ad-AwareGen:Variant.Zusy.320925
EmsisoftGen:Variant.Zusy.320925 (B)
ComodoTrojWare.Win32.Inject.ka@4o81ww
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebTrojan.DownLoad2.36100
ZillyaTrojan.InjectGen.Win32.4
TrendMicroTROJ_KRYPTK.SMS
McAfee-GW-EditionBehavesLike.Win32.Backdoor.mh
SophosML/PE-A + Troj/CeeInj-M
IkarusTrojan.Win32.Injector
AviraTR/Crypt.ZPACK.Gen
eGambitUnsafe.AI_Score_99%
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Inject.bbyo
MicrosoftTrojan:Win32/Dorv.A
ArcabitTrojan.Zusy.D4E59D
SUPERAntiSpywareBackdoor.Agent/Gen-Simbot
ZoneAlarmTrojan.Win32.Inject.bbyo
GDataGen:Variant.Zusy.320925
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.CSon.R7666
Acronissuspicious
McAfeeBackDoor-EYG
VBA32SScope.Backdoor.Simbot
MalwarebytesSimbot.Backdoor.Stealer.DDS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.ELH
TrendMicro-HouseCallTROJ_KRYPTK.SMS
TencentTrojan.Win32.Inject.bbyoa
YandexTrojan.GenAsa!5YxMY2U2QLk
SentinelOneStatic AI – Malicious PE – Spyware
MaxSecureTrojan.Inject.bbyo
FortinetW32/Injector.ELH!tr
BitDefenderThetaAI:Packer.721905D21F
AVGWin32:Taidoor-D [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.d1c

How to remove Zusy.320925?

Zusy.320925 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment