Malware

Zusy.433592 removal instruction

Malware Removal

The Zusy.433592 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.433592 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Checks adapter addresses which can be used to detect virtual network interfaces
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Likely virus infection of existing system binary
  • Attempts to modify proxy settings

How to determine Zusy.433592?


File Info:

name: 0085C893CF63381DBD78.mlw
path: /opt/CAPEv2/storage/binaries/535cd2fe2fb0e4b52d4e9cd68f5563752df509c46e39ecd0dd82bbfefad8cdd4
crc32: C051400B
md5: 0085c893cf63381dbd7856f446242d7c
sha1: b55e607f6a0a2bbfeb4a70e8a8014cce049462f4
sha256: 535cd2fe2fb0e4b52d4e9cd68f5563752df509c46e39ecd0dd82bbfefad8cdd4
sha512: 14799cad4fc88ba948d53a5cf5ed9230141c449d3447c25b49363a7ea3c45cf9a5441697cca15436e62b90cc1e44958dbc1cfc14cef3e7b1c4d9a9936e7bdbed
ssdeep: 12288:LUJDshJ/OecsH5uaeYq9vAUul6ClUFd2kNdoddXvxTG9E2eXkynMTBzgUFzaoUer:LUMG66vBd2txTKeXkz1RaoUSjwXjA/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BE25CF9AF296F832F0A10C37CEDDBD94AFFA207D1A4314277A456F1B496165879320B3
sha3_384: 46ac9d3b2f50aa8cfd6726a7c7efc835c583aa781adb1ad7223093004c522b7844674040dd497a94ce98c919efc9f498
ep_bytes: f8eb1d220a6315f9d4624813a9b22845
timestamp: 2015-08-20 04:22:58

Version Info:

0: [No Data]

Zusy.433592 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.433592
FireEyeGeneric.mg.0085c893cf63381d
CAT-QuickHealTrojan.FlystudioRI.S28136150
McAfeeFlyagent.d
CylanceUnsafe
ZillyaAdware.BrowseFox.Win32.306325
Sangfor[ARMADILLO V1.71]
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaGen:NN.ZexaF.34806.8qW@aaEFs@ai
VirITTrojan.Win32.Generic.CEBM
CyrenW32/Graftor.CS.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
ClamAVWin.Malware.Flystudio-9752414-0
KasperskyVHO:Trojan.Win32.Convagent.gen
BitDefenderGen:Variant.Zusy.433592
NANO-AntivirusVirus.Win32.Agent.dvixmz
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10c379b3
Ad-AwareGen:Variant.Zusy.433592
EmsisoftGen:Variant.Zusy.433592 (B)
ComodoWorm.Win32.Dropper.RA@1qraug
F-SecureHeuristic.HEUR/AGEN.1212399
VIPREGen:Variant.Zusy.433592
McAfee-GW-EditionBehavesLike.Win32.Trojan.dc
Trapminemalicious.high.ml.score
SophosMal/Behav-004
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1Y1PJNF
JiangminVariant.Jaik.cj
AviraHEUR/AGEN.1212399
Antiy-AVLTrojan/Win32.SGeneric
ArcabitTrojan.Zusy.D69DB8
ZoneAlarmVHO:Trojan.Win32.Convagent.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Gen
VBA32BScope.Trojan.Downloader
ALYacGen:Variant.Zusy.433592
MAXmalware (ai score=83)
MalwarebytesEmotet.Trojan.Stealer.DDS
RisingTrojan.Spawnerx!1.C489 (CLASSIC)
YandexTrojan.GenAsa!3gHWr/9wsOM
IkarusTrojan.Crypt
FortinetW32/CoinMiner.BELF!tr
AVGWin32:Malware-gen
Cybereasonmalicious.f6a0a2

How to remove Zusy.433592?

Zusy.433592 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment