Malware

What is “Zusy.385159”?

Malware Removal

The Zusy.385159 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.385159 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Zusy.385159?


File Info:

name: 142E07486DB458AD4E80.mlw
path: /opt/CAPEv2/storage/binaries/de226da3dc5c052762bce97b3d5f5fa7c518024ecc815d3e6e44a8a5a7cf84ed
crc32: AEF6AE9E
md5: 142e07486db458ad4e807caa63cb91ec
sha1: 631589ab2074489fb38d4fc62ab49a2608dab8b5
sha256: de226da3dc5c052762bce97b3d5f5fa7c518024ecc815d3e6e44a8a5a7cf84ed
sha512: 74266dfea574d9cad83c33405bfcad856eec5e35af576a370c52a63edd87b555378bd3bd1c381bf6567f1f9f786e6fe21f06571745b8b31d404cb96a04bd2e29
ssdeep: 192:Ly+wx8n9sYWwOqyrCC2F7VkUJNXHPnQUOCjcl33K90O0:R0xrCVF7VkUjHPnQUOCj0Hc0O0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10E72420EFFD1CB63D24252B925A983510FA6AFFC5E25D656A445BD0D3A3C340BF1E281
sha3_384: d952a23a0a59ed3af5198ec71201e80687d05a685dc6731d9bcf98c0f982c2551d56d6426bddaa3ed9f85e4a6fb3ab7e
ep_bytes: 6a00ff151c314000a35a1e4000ff15cc
timestamp: 2018-12-25 08:33:12

Version Info:

Comments: Friendly Password Generator
CompanyName: ManHunter / PCL (www.manhunter.ru)
FileDescription: Friendly Password Generator
FileVersion: 1.7.0.2
InternalName: Friendly Password Generator
LegalCopyright: ManHunter / PCL
ProductName: Friendly Password Generator
ProductVersion: 1.7.0.2
Translation: 0x0409 0x04e4

Zusy.385159 also known as:

BkavW32.AIDetect.malware1
CynetMalicious (score: 100)
FireEyeGeneric.mg.142e07486db458ad
McAfeeRDN/Ransom
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusRiskware ( 0040eff71 )
AlibabaRansom:Win32/DelFile.f668a7be
K7GWRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.JENDXLG
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Ransom.Win32.Gen.kxd
BitDefenderGen:Variant.Zusy.385159
SUPERAntiSpywareTrojan.Agent/Gen-Razy
MicroWorld-eScanGen:Variant.Zusy.385159
AvastWin32:MalwareX-gen [Trj]
TencentWin32.Trojan.Gen.Dvgg
Ad-AwareGen:Variant.Zusy.385159
EmsisoftGen:Variant.Zusy.385159 (B)
ComodoMalware@#2vdohb4i4wyfk
ZillyaTrojan.Gen.Win32.1945
TrendMicroRansom_Gen.R002C0WKN21
McAfee-GW-EditionRDN/Ransom
SophosMal/Generic-S
IkarusTrojan.DelFile
GDataGen:Variant.Zusy.385159
JiangminTrojan.Gen.aan
eGambitUnsafe.AI_Score_99%
AviraTR/DelFile.rxqcs
Antiy-AVLTrojan/Generic.ASMalwS.2A5962E
GridinsoftRansom.Win32.Occamy.sa
ViRobotTrojan.Win32.Z.Agent.16384.OPY
MicrosoftTrojan:Win32/Occamy.CDE
AhnLab-V3Malware/Win32.Generic.C2906167
BitDefenderThetaGen:NN.ZexaF.34294.bq0@aCuZ2Rei
ALYacGen:Variant.Zusy.385159
MAXmalware (ai score=99)
VBA32BScope.TrojanRansom.Gen
MalwarebytesMalware.AI.2964764841
TrendMicro-HouseCallRansom_Gen.R002C0WKN21
RisingTrojan.Generic@ML.82 (RDMK:snl1vGD8QJdCdoSrhC+9ZA)
YandexTrojan.GenAsa!wF8tBhAPJIY
SentinelOneStatic AI – Malicious PE
FortinetW32/Generic.AP.254E64!tr
WebrootW32.Malware.Gen
AVGWin32:MalwareX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Zusy.385159?

Zusy.385159 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment