Malware

Zusy.425390 removal

Malware Removal

The Zusy.425390 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.425390 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • CAPE detected the embedded win api malware family
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Zusy.425390?


File Info:

name: DFA266CAE7BAF42E18FB.mlw
path: /opt/CAPEv2/storage/binaries/dadc3c05c8415e0913e559415acd02d89ff009a68083441e65b0b33b25825890
crc32: D2EB6024
md5: dfa266cae7baf42e18fb4117eaf34a30
sha1: 0849a1f72f669d5789cb5ff1f2a4142f9b8ab40f
sha256: dadc3c05c8415e0913e559415acd02d89ff009a68083441e65b0b33b25825890
sha512: ea055f774461f05f29fa302c91b779db921ccb4f567618dfa9133daac7c0556a3317f916253bdf7ce6d24964a33d5ce4568b8d3743c59c6375a546ec556c7d20
ssdeep: 6144:/sMryq8yLMIeJ0lVYKHD7i44KOzgeGB5y:LyfTJwVa4dT5y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11B44129266464D99C07C4ABA1058DFB815BFECE83F13361A20D8727F3A23635BA05F57
sha3_384: 9f72b44df18dd50f86b506bb51ff0b8a306d7c10ae4097aef37392ea455235710440e9301c594b5ac368ee59fdae21f0
ep_bytes: 558bec83ec085756ba1ba40000c745fc
timestamp: 2002-06-01 16:58:33

Version Info:

FileVersion: 9.8.3.5
ProductVersion: 6.2.8.0
FileDescription: drias
CompanyName: Xtreeme
LegalCopyright: kaka
ProductName: Underwent
Translation: 0x0000 0x04b0

Zusy.425390 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
DrWebTrojan.Packed.20771
MicroWorld-eScanGen:Variant.Zusy.425390
FireEyeGeneric.mg.dfa266cae7baf42e
SkyhighBehavesLike.Win32.PWSZbot.dc
ALYacGen:Variant.Zusy.425390
Cylanceunsafe
ZillyaBackdoor.Shiz.Win32.1631
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Simda.61d50861
K7GWSpyware ( 005068aa1 )
K7AntiVirusSpyware ( 005068aa1 )
BitDefenderThetaGen:NN.ZexaF.36802.qO0@aSORbqfi
VirITTrojan.Win32.SHeur4.JWT
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.XEO
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Agent-333031
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.425390
NANO-AntivirusTrojan.Win32.Agent.rgfcz
AvastWin32:MalOb-IJ [Cryp]
TencentMalware.Win32.Gencirc.10b4095d
EmsisoftGen:Variant.Zusy.425390 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREGen:Variant.Zusy.425390
TrendMicroTROJ_RUNLOAD.USBD03AVC
Trapminemalicious.high.ml.score
SophosMal/EncPk-ACR
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.425390
JiangminTrojan/Generic.sbhd
VaristW32/Shiz.YHWI-1391
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.Unknown
KingsoftWin32.Trojan.Generic.a
XcitiumTrojWare.Win32.Kryptik.XDY@4oc6hk
ArcabitTrojan.Zusy.D67DAE
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Simda.A
GoogleDetected
AhnLab-V3Backdoor/Win32.Shiz.R141129
McAfeeGeneric BackDoor.acx
MAXmalware (ai score=100)
VBA32BScope.Trojan.Diple
MalwarebytesMalware.Heuristic.2069
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_RUNLOAD.USBD03AVC
RisingBackdoor.Simda!8.2D9 (TFE:1:Cni3XxDPYiN)
YandexBackdoor.Shiz!OEKGuUCN6a0
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Shiz.YWP!tr.bdr
AVGWin32:MalOb-IJ [Cryp]
DeepInstinctMALICIOUS
alibabacloudBackdoor:Win/Simda.A

How to remove Zusy.425390?

Zusy.425390 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment