Malware

Zusy.426962 (file analysis)

Malware Removal

The Zusy.426962 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.426962 virus can do?

  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Zusy.426962?


File Info:

name: 5A2A48A0B19C78577636.mlw
path: /opt/CAPEv2/storage/binaries/5d3c1a3a79a38124fdb04fcba5aec75bc62c4cdecb1abe524b3a965930a25a6a
crc32: 6742D9CB
md5: 5a2a48a0b19c785776360b8f00b94e36
sha1: abacc7027b1e764e987b722124d88466117b261c
sha256: 5d3c1a3a79a38124fdb04fcba5aec75bc62c4cdecb1abe524b3a965930a25a6a
sha512: 68be79c382670c2e81aff8b3ebe2b01d8a8983fa4c64909390fe24d78f9ea3caf4bbcf26896765b033dd5c73f0b49347094b24c9de81db46d0e3af1c2ee71735
ssdeep: 6144:JAN5Ify5IGdnqyaVZAf4LTnq553sJAvK9eKoe61inJrhaIgpVVEW:JAAfy5ldnoZAf4Pq553sWSeKrNJrhFM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T147948D23B784E032D01302B1AE16DB78E5B9B8B1E9360147B7D85B1DAFB45C29A35F43
sha3_384: f492ae35625b4877e63a23daaba536db7fe10f049a3778f0858c413062aeacfd1eae35a299fc56e58a40662dda7e7b4e
ep_bytes: e8087e0000e979feffffcccccccccccc
timestamp: 2014-11-19 13:18:54

Version Info:

0: [No Data]

Zusy.426962 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.5a2a48a0b19c7857
CAT-QuickHealDownloader.Lmn.6035
McAfeePUP-XIX-PR
CylanceUnsafe
VIPREGen:Variant.Zusy.426962
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 004b87be1 )
K7GWAdware ( 004b87be1 )
Cybereasonmalicious.0b19c7
CyrenW32/LoadMoney.EU.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Adware.LoadMoney.RM
APEXMalicious
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderGen:Variant.Zusy.426962
NANO-AntivirusTrojan.Win32.LoadMoney.drsmrj
MicroWorld-eScanGen:Variant.Zusy.426962
AvastWin32:Adware-gen [Adw]
TencentMalware.Win32.Gencirc.10d09fc5
Ad-AwareGen:Variant.Zusy.426962
EmsisoftGen:Variant.Zusy.426962 (B)
ComodoTrojWare.Win32.Rogue.OOTF@5bltcy
F-SecureAdware.ADWARE/Adware.Gen4
DrWebTrojan.LoadMoney.386
ZillyaAdware.LoadMoneyGen.Win32.4
McAfee-GW-EditionPUP-XIX-PR
SophosGeneric PUA KL (PUA)
IkarusVirus.Win32.Cryptor
GDataGen:Variant.Zusy.426962
JiangminDownloader.Generic.arzz
AviraADWARE/Adware.Gen4
Antiy-AVLGrayWare[AdWare]/Win32.LoadMoney
ArcabitTrojan.Zusy.D683D2
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
MicrosoftProgram:Win32/Wacapew.C!ml
GoogleDetected
AhnLab-V3PUP/Win32.RL_Generic.R303394
VBA32SScope.Downware.LMN
ALYacGen:Variant.Zusy.426962
MAXmalware (ai score=84)
RisingTrojan.Occamy!8.F1CD (TFE:5:3r12NGC4FUC)
YandexTrojan.GenAsa!9Knk4398WWI
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/LoadMoney.RM
BitDefenderThetaGen:NN.ZexaCO.34646.zqW@aWENRRpk
AVGWin32:Adware-gen [Adw]
PandaTrj/Genetic.gen

How to remove Zusy.426962?

Zusy.426962 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment