Malware

Zusy.420662 malicious file

Malware Removal

The Zusy.420662 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.420662 virus can do?

  • Uses Windows utilities for basic functionality
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Zusy.420662?


File Info:

name: 10616CBE5409F845061E.mlw
path: /opt/CAPEv2/storage/binaries/6de218559268ee26016ac169f7d2898626c9328d9e588275867566a833416d45
crc32: 0F0D1DA8
md5: 10616cbe5409f845061ef968cfba7aa1
sha1: 616bc6f7616b7b933c2ed9d5350af56439e0a852
sha256: 6de218559268ee26016ac169f7d2898626c9328d9e588275867566a833416d45
sha512: 2c320a04967a4d285ae09da1088ad51cdeda64ff121e5d3da979e11bee622fd07edb179184cfde60a492455fda6e8cbdceecb252982be0db2d9c65671a942d8d
ssdeep: 384:VieUVMAy4u9XhI5ghjM1FLHJ4O5Anh9o+O4gxroY1gLWFuQYV+:o7VMAy4u9XS5GjMOQGXQtgKQtV+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EEA2083D93CFAA1BF3C63D3070324632977C89621B0686B5FA6D175C3C9692C9A6035B
sha3_384: 422393e7d94ff6dd3449a20077a3c1ddb29eb1981972377204e9c7495d9b90a2179eee8854dd297f26491711714dbe65
ep_bytes: 4d5ae9ca6500000004000000ffff0000
timestamp: 2010-07-24 14:44:02

Version Info:

CompanyName:
FileDescription: gameupdate Microsoft 基础类应用程序
FileVersion: 1, 0, 0, 1
InternalName: gameupdate
LegalCopyright: 版权所有 (C) 2010
LegalTrademarks:
OriginalFilename: gameupdate.EXE
ProductName: gameupdate 应用程序
ProductVersion: 1, 0, 0, 1
Translation: 0x0804 0x04b0

Zusy.420662 also known as:

LionicTrojan.Win32.Agent.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.420662
SkyhighBehavesLike.Win32.Infected.mm
ALYacGen:Variant.Zusy.420662
MalwarebytesMalware.Heuristic.1001
VIPREGen:Variant.Zusy.420662
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040f5651 )
BitDefenderGen:Variant.Zusy.420662
K7GWTrojan ( 0040f5651 )
Cybereasonmalicious.7616b7
BaiduWin32.Trojan-Downloader.Agent.hi
VirITTrojan.Win32.X-PolyCrypt.B
SymantecTrojan.Gen
ESET-NOD32Win32/TrojanDownloader.Agent.QDK
APEXMalicious
ClamAVWin.Trojan.Agent-511688
KasperskyTrojan-Downloader.Win32.Agent.efjd
AlibabaTrojanDownloader:Win32/Bulilit.1b790992
NANO-AntivirusTrojan.Win32.Agent.ddzde
ViRobotTrojan.Win.Z.Agent.21504.DQ
RisingTrojan.Generic@AI.96 (RDML:0KYUsKAQdOMiTs/SPq87BA)
SophosMal/Behav-004
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.MulDrop1.40512
ZillyaDownloader.Agent.Win32.69967
TrendMicroTROJ_SMALL.SMOK
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.10616cbe5409f845
EmsisoftGen:Variant.Zusy.420662 (B)
IkarusTrojan-Downloader.Win32.Bulilit
MAXmalware (ai score=100)
JiangminTrojan/Generic.ahae
WebrootW32.Malware.Downloader
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/SmallTrojan.U.gen!Eldorado
Antiy-AVLTrojan[Downloader]/Win32.Agent
MicrosoftTrojanDownloader:Win32/Bulilit.A
XcitiumMalware@#3l8zoleq0zpgb
ArcabitTrojan.Zusy.D66B36
ZoneAlarmTrojan-Downloader.Win32.Agent.efjd
GDataGen:Variant.Zusy.420662
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win32.Small.R2886
Acronissuspicious
VBA32Malware-Cryptor.Win32.Vals.22
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_SMALL.SMOK
TencentWin32.Trojan-Downloader.Agent.Ekjl
YandexTrojan.DL.Agent!+UXgOF0+RsM
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1547509.susgen
FortinetW32/PePatch.W!tr
BitDefenderThetaGen:NN.ZexaF.36792.biW@aWOcyzp
AVGWin32:Agent-ALUJ [Drp]
AvastWin32:Agent-ALUJ [Drp]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Zusy.420662?

Zusy.420662 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment