Malware

Zusy.385046 removal guide

Malware Removal

The Zusy.385046 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.385046 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Zusy.385046?


File Info:

name: 39E5F1A83970B434C35A.mlw
path: /opt/CAPEv2/storage/binaries/54fc13187c49f52e206bcb31e980ed8195456b6025ed7d80ce05b943d3168eec
crc32: 16D0D86A
md5: 39e5f1a83970b434c35ae2e3c2ed6701
sha1: 5600d182903c1d28f49e5586b7b9f17454055863
sha256: 54fc13187c49f52e206bcb31e980ed8195456b6025ed7d80ce05b943d3168eec
sha512: 9a8e0ba61bdb2aeea88a4b613f022d29cc01f7bf9a14263d8d2aa5870b639c41fbceb5ba52133804a5321429b90ca978df62d9021629c9042b2a456008073f2e
ssdeep: 49152:Obz7wOtjhXbpl5HEnqftDwIBenf6KNMfA3T4dWICAqDkkhEuzjFfWP:Ob3fjhXLBEnS0IBef6KTT+WIHgkmVtC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T154C533037159A4B0EACA9B7E80136D4E5D5BE338E8ECFF86C5016509A8BDBC35E0857D
sha3_384: 8dfdd7d7adb99fc0626a78390af54efc1ac199ab79bce36fc1d5c7cff983b99d82b97568c4ccdea63b707220995edd9c
ep_bytes: 9c55539cc744240cfe8ebbb4c704249e
timestamp: 2016-10-19 16:20:22

Version Info:

0: [No Data]

Zusy.385046 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.385046
FireEyeGeneric.mg.39e5f1a83970b434
McAfeeGenericRXAA-AA!39E5F1A83970
ZillyaTool.GameHack.Win32.10615
K7AntiVirusRiskware ( 0055997e1 )
K7GWRiskware ( 0055997e1 )
Cybereasonmalicious.83970b
BitDefenderThetaGen:NN.ZexaF.34062.AUZ@a82MWQkj
CyrenW32/OnlineGames.CP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/RiskWare.GameHack.DP
TrendMicro-HouseCallTROJ_GEN.R035H0CL621
ClamAVWin.Malware.Razy-9646838-0
BitDefenderGen:Variant.Zusy.385046
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10cf00e0
Ad-AwareGen:Variant.Zusy.385046
EmsisoftGen:Variant.Zusy.385046 (B)
VIPRETrojan.Win32.OnlineGames
McAfee-GW-EditionBehavesLike.Win32.PUPXBO.vc
SophosGeneric ML PUA (PUA)
IkarusTrojan.Spy.Banker
GDataGen:Variant.Zusy.385046
eGambitUnsafe.AI_Score_90%
AviraHEUR/AGEN.1103221
Antiy-AVLTrojan/Generic.ASMalwS.207E2E1
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
VBA32BScope.Trojan.MulDrop
ALYacGen:Variant.Zusy.385046
MAXmalware (ai score=88)
CylanceUnsafe
APEXMalicious
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazrGdd5LXTK2VocCnpCGPDKR)
YandexTrojan.GenAsa!P79O5FW7VUI
SentinelOneStatic AI – Malicious PE
FortinetRiskware/GameHack
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Zusy.385046?

Zusy.385046 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment