Categories: Malware

Zusy.390513 removal

The Zusy.390513 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.390513 virus can do?

  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Zusy.390513?


File Info:

name: 4DC41992CBEA0494CF3B.mlwpath: /opt/CAPEv2/storage/binaries/2f43105027f23c16461df23635fab19a6a2635b90efef4cf2300115e316ee448crc32: 4E7A9041md5: 4dc41992cbea0494cf3b576599d08606sha1: e19fe258957eb6461d717ee4f45a2eff8fa16410sha256: 2f43105027f23c16461df23635fab19a6a2635b90efef4cf2300115e316ee448sha512: a223a290d4f5e24ecc9af6b5287c83598a0c88c8177471e1adb7dd95f15ad9a5c53a9bb8f7c047aaa3d55ee93ee1ae44782466d14c4cb3ff165cccbbd6c3e6ebssdeep: 98304:vOAqw+gANU0DKPbAT+Rq2vcv1+agUmHUqU1B56GAH7TvmfuwD4:vO5gAN9uMaU2q+adAU1BYTv8j0type: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T19F262327B6BEC2F0F8AD3EF456406B525972AE651A35E087C51F7CC4E933283D8296C4sha3_384: 3e015ebb875ff39ecc0dfd134fd0a16cc9b097ee750ca401183928a0b73c36b16a6551c6a309372cd8e75f248e9019f9ep_bytes: 558bec6aff6878c3410068c092410064timestamp: 2012-05-10 11:37:50

Version Info:

CompanyName: Oleg N. ScherbakovFileDescription: 7z Setup SFX (x86)FileVersion: 1.6.0.2478InternalName: 7ZSfxModLegalCopyright: Copyright © 2005-2012 Oleg N. ScherbakovOriginalFilename: 7ZSfxMod_x86.exePrivateBuild: May 10, 2012ProductName: 7-Zip SFXProductVersion: 1.6.0.2478Translation: 0x0000 0x04b0

Zusy.390513 also known as:

Lionic Trojan.Win32.Crypzip.4!c
MicroWorld-eScan Gen:Variant.Zusy.390513
FireEye Gen:Variant.Zusy.390513
ALYac Gen:Variant.Zusy.390513
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Trojan.Win32.Crypzip.fi
K7AntiVirus Trojan ( 0057e80b1 )
Alibaba Trojan:Win32/Crypzip.8da60b8e
K7GW Trojan ( 0057e80b1 )
Cyren W32/Trojan.QRCQ-2906
Symantec Trojan.Gen.MBT
ESET-NOD32 a variant of Win32/Packed.7zip.CP suspicious
Kaspersky Trojan.Win32.Crypzip.fi
BitDefender Gen:Variant.Zusy.390513
Avast Win32:Malware-gen
Tencent Win32.Trojan.Crypzip.Phgu
Ad-Aware Gen:Variant.Zusy.390513
Emsisoft Gen:Variant.Zusy.390513 (B)
TrendMicro TROJ_GEN.R007C0WHO21
McAfee-GW-Edition BehavesLike.Win32.BadFile.rc
Sophos Mal/Generic-S
GData Gen:Variant.Zusy.390513
Jiangmin HackTool.KMSAuto.gr
MaxSecure Trojan.Malware.116864819.susgen
Avira TR/Redcap.lssww
MAX malware (ai score=80)
Microsoft Trojan:Win32/Wacatac.B!ml
Cynet Malicious (score: 99)
McAfee Artemis!4DC41992CBEA
VBA32 Trojan.Crypzip
Malwarebytes Trojan.Dropper.Generic
TrendMicro-HouseCall TROJ_GEN.R007C0WHO21
Rising Trojan.HiddenRun/SFX!1.D57B (CLASSIC)
Yandex Trojan.Crypzip!kqJCN3NA8zI
Fortinet Riskware/Crypzip
AVG Win32:Malware-gen
Panda Trj/CI.A

How to remove Zusy.390513?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Generic.OrcusRAT.A.29F3E0AA removal

The Generic.OrcusRAT.A.29F3E0AA is considered dangerous by lots of security experts. When this infection is active,…

19 mins ago

What is “Win32/Rozena.BGJ”?

The Win32/Rozena.BGJ is considered dangerous by lots of security experts. When this infection is active,…

55 mins ago

What is “Barys.237529”?

The Barys.237529 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Cerbu.90700 malicious file

The Cerbu.90700 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Malware.AI.1463468154 removal

The Malware.AI.1463468154 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Generic.Dacic.94CCEEA9.A.D9367AEB malicious file

The Generic.Dacic.94CCEEA9.A.D9367AEB is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago