Malware

Zusy.395254 information

Malware Removal

The Zusy.395254 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.395254 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Zusy.395254?


File Info:

name: BC492A30F0A360E234FC.mlw
path: /opt/CAPEv2/storage/binaries/7d86acffa1564a2846a5007f7a69a154e848770399efcc3b1cd4c7a051bdea89
crc32: AE2CFEC1
md5: bc492a30f0a360e234fc3f0fe44bc314
sha1: d7ed4609bc79de2225d4d8e648a5bd371903e9f8
sha256: 7d86acffa1564a2846a5007f7a69a154e848770399efcc3b1cd4c7a051bdea89
sha512: 0e8828aa3e17b23e2d0c94bc4864f05654f686b1fa461b9da52c8825369aea50047560b27539e3abf181432c9778969e84ac33c9d718d839bbbb8028bcc9c059
ssdeep: 12288:Q6KSmVhafvmEQ9Ril2S3JwiIAyuOQrRPl:Q6KSmV0C9Ql1zDbr3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EA75AA31B7C1ACADC241FA31267A9C004D165E5E3F38469F3F4B71661FF2E4A20A9D5A
sha3_384: e382d9cb032298f402563a6311852eccf5208bc10ace301f214d38d83e62887226133c7a53f6463260e62b292ffbda29
ep_bytes: 558bec6aff6800b5460068ce9c460064
timestamp: 2021-07-25 08:17:02

Version Info:

CompanyName: ATTO Technology Inc.
FileDescription: ATTO Disk Benchmark
FileVersion: 4.1.0.0
InternalName: ATTO Disk Benchmark
LegalCopyright: Copyright © 1994-2019 ATTO Technology Inc.
OriginalFilename: ATTODiskBenchmark.exe
ProductName: ATTO Disk Benchmark
ProductVersion: 4.1.0.0
Translation: 0x0409 0x04b0

Zusy.395254 also known as:

BkavW32.ToadoraAD.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.395254
FireEyeGeneric.mg.bc492a30f0a360e2
ALYacGen:Variant.Zusy.395254
Sangfor[ARMADILLO V1.71]
K7AntiVirusTrojan ( 005821bc1 )
K7GWTrojan ( 005821bc1 )
Cybereasonmalicious.9bc79d
BitDefenderThetaGen:NN.ZexaF.34742.Hz0@amiBZGpi
CyrenW32/Zusy.GR.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HLQM
BitDefenderGen:Variant.Zusy.395254
AvastWin32:CrypterX-gen [Trj]
TencentTrojan.Win32.Staser.za
Ad-AwareGen:Variant.Zusy.395254
EmsisoftGen:Variant.Zusy.395254 (B)
VIPREGen:Variant.Zusy.395254
SentinelOneStatic AI – Malicious PE
Trapminemalicious.high.ml.score
IkarusTrojan.Win32.Crypt
AviraHEUR/AGEN.1244176
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.18W14TU
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R434539
Acronissuspicious
McAfeeGenericRXAA-AA!BC492A30F0A3
MalwarebytesAdware.DownloadAssistant
APEXMalicious
RisingTrojan.Kryptik!1.AA55 (CLASSIC)
MAXmalware (ai score=88)
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.HATU!tr
AVGWin32:CrypterX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Zusy.395254?

Zusy.395254 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment