Malware

Zusy.437511 malicious file

Malware Removal

The Zusy.437511 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.437511 virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Emumerates physical drives
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.437511?


File Info:

name: 3BE28A5F1EDD0B49EAE6.mlw
path: /opt/CAPEv2/storage/binaries/5b6be58166e675aa10fa74772e85c6a554ead0fba0e9d80e756b3481d073afdb
crc32: F27C05E1
md5: 3be28a5f1edd0b49eae69a2b0d59c351
sha1: 0500f29b9848d5e3aa862b5dfbb3266245c9e113
sha256: 5b6be58166e675aa10fa74772e85c6a554ead0fba0e9d80e756b3481d073afdb
sha512: cd39ab8d6809e15b5254bc192ca70bf8631b600679fa9335963f9b0a8dd7b4d76bec40df8507ba185ec081444f8993b601b35a28274d344649f1b5f8b8c453bb
ssdeep: 6144:RBpL80E7VmvskXreQ0Go4SMCkboXsOvaQK:DR80EZmvXXreQ0Go4SMCkboXs0lK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BA2428232D74C573F6311930DAEC16F4B3F9EB5D0E21545BB384473D6EBA9638122A2A
sha3_384: 9e4b9da02a54d69c6f0aa5cb590936f2c224968eb6f507302267722a821a27d25980d0bb8f9550b9b7d1ae79add8b2dd
ep_bytes: 558bec6aff68b0984200685c46420064
timestamp: 2015-03-03 14:03:26

Version Info:

0: [No Data]

Zusy.437511 also known as:

BkavW32.Common.68A7FB17
LionicTrojan.Win32.Bingoml.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.437511
CAT-QuickHealTrojan.GenericPMF.S30656940
SkyhighBehavesLike.Win32.PWSZbot.dh
McAfeeArtemis!3BE28A5F1EDD
MalwarebytesGeneric.Adware.Agent.DDS
VIPREGen:Variant.Zusy.437511
SangforAdware.Win32.Bingoml.Vvxx
K7AntiVirusAdware ( 004b8cfc1 )
BitDefenderGen:Variant.Zusy.437511
K7GWAdware ( 004b8cfc1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.ICLoader.IC
APEXMalicious
KasperskyHEUR:Trojan.Win32.Bingoml.gen
AlibabaTrojan:Win32/Bingoml.416a388c
NANO-AntivirusTrojan.Win32.Bingoml.jrrtwg
ViRobotAdware.Icloader.229376.EO
RisingTrojan.Bingoml!8.1226A (TFE:5:mJe8m1qyP2C)
SophosGeneric Reputation PUA (PUA)
DrWebTrojan.InstallCube.67
ZillyaAdware.ICLoader.Win32.18398
FireEyeGeneric.mg.3be28a5f1edd0b49
EmsisoftGen:Variant.Zusy.437511 (B)
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=87)
JiangminTrojan.Bingoml.giw
GoogleDetected
VaristW32/ICloader.BZ.gen!Eldorado
Antiy-AVLGrayWare[AdWare]/Win32.ICLoader
Kingsoftmalware.kb.a.832
MicrosoftPUADlManager:Win32/InstallCube
ArcabitTrojan.Zusy.D6AD07
ZoneAlarmHEUR:Trojan.Win32.Bingoml.gen
GDataGen:Variant.Zusy.437511
CynetMalicious (score: 100)
AhnLab-V3Adware/Win.Generic.R513112
VBA32Downware.ICloader.gen
ALYacGen:Variant.Zusy.437511
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H0CH323
TencentTrojan.Win32.Bingoml.hbq
IkarusPUA.ICLoader
MaxSecureTrojan.Malware.109135027.susgen
FortinetAdware/ICLoader
AVGWin32:Adware-gen [Adw]
AvastWin32:Adware-gen [Adw]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Zusy.437511?

Zusy.437511 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment