Malware

Zusy.435398 (B) malicious file

Malware Removal

The Zusy.435398 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.435398 (B) virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Zusy.435398 (B)?


File Info:

name: 6C62125013A814DF7AA9.mlw
path: /opt/CAPEv2/storage/binaries/eee34f98137f2cc2c47b7c21346f5eabda2e68f4c7f7401b934679ad5660ff4a
crc32: C492A51B
md5: 6c62125013a814df7aa950c04300f192
sha1: accced534a72909487fb490aead3530459ed9635
sha256: eee34f98137f2cc2c47b7c21346f5eabda2e68f4c7f7401b934679ad5660ff4a
sha512: 472c3ef9e9a8c6c3e419d3e42514896bf2cd9f38edecd0ee5c826ddcb84d551073621009d6f925b3df512a862f3e61f8cfbfeb34ca700f1cd671bdeee790f30d
ssdeep: 1536:VDJ5/qvHSRyepF3HQILQcdeIiqMldulhmwMMRdloNyC6436g6rp6g6s6g6sQca:V3d10Lulh8MRv6yC6FQc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15544C302B2B18525E1F63A36CF76C6E40B25BCF57D35CE0A22A47D4F3A71A079825367
sha3_384: 3279b112396056c19b7510212b2f9e17161916b0d32aed294a6d4c76402ecdfb4330d421f035f4f492ebc13a73505e97
ep_bytes: 60be00a046008dbe0070f9ffc787a420
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Zusy.435398 (B) also known as:

BkavW32.AIDetect.malware2
DrWebBackDoor.Click.1197
MicroWorld-eScanGen:Variant.Zusy.435398
FireEyeGeneric.mg.6c62125013a814df
ALYacGen:Variant.Zusy.435398
CylanceUnsafe
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.34a729
BitDefenderThetaGen:NN.ZexaF.34784.pmW@a0RHbWhb
CyrenW32/Bingoml.E.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
APEXMalicious
BitDefenderGen:Variant.Zusy.435398
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Zusy.435398
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/Crypt.ULPM.Gen
VIPREGen:Variant.Zusy.435398
McAfee-GW-EditionArtemis
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Zusy.435398 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Zusy.435398
GoogleDetected
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.256
ArcabitTrojan.Zusy.D6A4C6
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Generic.R457493
Acronissuspicious
McAfeeArtemis!6C62125013A8
MalwarebytesMalware.AI.3208989678
YandexTrojan.ULPM!KwqLAAWg+lw
IkarusTrojan.Win32.Buzus
MaxSecureTrojan.Malware.7175209.susgen
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Zusy.435398 (B)?

Zusy.435398 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment