Malware

Should I remove “Zusy.404235”?

Malware Removal

The Zusy.404235 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.404235 virus can do?

  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

stat.kuai8box.com

How to determine Zusy.404235?


File Info:

crc32: BA86A6B6
md5: 981c5d38c61b9cd13712470aad81d315
name: 981C5D38C61B9CD13712470AAD81D315.mlw
sha1: 75e85ac3dede3f232e704b0279cc90be79e98211
sha256: a76abc1e40a896f67f2410ae77f6b7e6c94fc03ea2dc4aae662ed01f1d0733f6
sha512: 6be2502b43b4a304d1507d563d43e7671653f0439f6357662586707d7daf929d10af123e15f4f67fc72d73709d386f4c73bdaf81ecc786ff23fd999b40c80d00
ssdeep: 24576:mW1T3yGG9gMZzUCZhsRAtkEi0Rr6sE5CXHwONgZvYAEZVyT/RE:WkaIA2ksZvJEZ8T/K
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2015-2020
InternalName: x6e38x620fx5b89x88c5x7a0bx5e8f
FileVersion: 1, 0, 0, 8337
ProductName: x6e38x620fx5b89x88c5x7a0bx5e8f
ProductVersion: 1, 0, 0, 8337
FileDescription: x6e38x620fx5b89x88c5x7a0bx5e8f
OriginalFilename: yunpan.exe
Translation: 0x0804 0x04b0

Zusy.404235 also known as:

K7AntiVirusAdware ( 005636321 )
LionicAdware.Win32.Agent.2!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.Zusy.404235
CylanceUnsafe
SangforAdware.Win32.Agent.gen
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/Kuaiba.97586cf0
K7GWAdware ( 005636321 )
Cybereasonmalicious.8c61b9
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Kuaiba.N
APEXMalicious
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:HEUR:AdWare.Win32.Agent.gen
BitDefenderGen:Variant.Zusy.404235
MicroWorld-eScanGen:Variant.Zusy.404235
TencentMalware.Win32.Gencirc.10cf62cd
Ad-AwareGen:Variant.Zusy.404235
SophosGeneric PUA HF (PUA)
TrendMicroTROJ_GEN.R002C0WJV21
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.981c5d38c61b9cd1
EmsisoftGen:Variant.Zusy.404235 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1119863
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.A!ml
ArcabitTrojan.Zusy.D62B0B
GDataGen:Variant.Zusy.404235
McAfeeGenericRXAA-AA!981C5D38C61B
MAXmalware (ai score=86)
VBA32BScope.Adware.Kuaiba
MalwarebytesPUP.Optional.ChinAd
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0WJV21
YandexPUA.Agent!uYXpCplHRb8
MaxSecureTrojan.Malware.12142041.susgen
FortinetRiskware/Kuaiba
AVGWin32:Adware-gen [Adw]

How to remove Zusy.404235?

Zusy.404235 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment