Malware

Zusy.438036 information

Malware Removal

The Zusy.438036 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.438036 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Zusy.438036?


File Info:

name: E0F848C25A7BD08E4A68.mlw
path: /opt/CAPEv2/storage/binaries/15d5e0648db396f89a20f5b8434442090497f3b5724d6b8a101532ad8beffc13
crc32: 67509A99
md5: e0f848c25a7bd08e4a68cca4066e9671
sha1: 02f8169b7000f21df5d396f9db3c36451226de67
sha256: 15d5e0648db396f89a20f5b8434442090497f3b5724d6b8a101532ad8beffc13
sha512: c7872323835805ba83b088af7493c7c22c0c184b799204b5d7820b60895354f77907a5b25f7863551e8ff96621e0563a40eda16de4e61a08d3b3b4268536d387
ssdeep: 98304:jKVD00R3d6V1AFD2yTGJ3r9P1lG4++E4Vzp9qX:Us9PlTK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CB265A23B402C491C1291BB222E55B382DB85F762C79C897EBE8FE76BD75532D75200E
sha3_384: 53565b91f6dd64793998ca1b1ddfb277fb448acc2107151953ed401fd1165c5c6752d20df51700932e510a7533f70c7a
ep_bytes: 558bec6aff68a88a7e0068089b660064
timestamp: 2022-11-09 03:37:12

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: MF_H5原始
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Zusy.438036 also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.438036
FireEyeGeneric.mg.e0f848c25a7bd08e
CAT-QuickHealTrojan.Generic.5550
ALYacGen:Variant.Zusy.438036
CylanceUnsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.b7000f
BitDefenderThetaGen:NN.ZexaF.34784.@t0@amcng5iH
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
ClamAVWin.Malware.Trojanx-9951053-0
BitDefenderGen:Variant.Zusy.438036
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Variant.Zusy.438036
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Kuluoz.DLL@5t8nbt
VIPREGen:Variant.Zusy.438036
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Zusy.438036 (B)
GDataWin32.Trojan.PSE.18JA6Q4
GoogleDetected
Antiy-AVLTrojan/Win32.FlyStudio.a
ArcabitTrojan.Zusy.D6AF14
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R497729
Acronissuspicious
MAXmalware (ai score=81)
VBA32BScope.Adware.Agent
MalwarebytesMalware.AI.2406103621
APEXMalicious
RisingTrojan.Kazy!1.6838 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.65CA!tr
AVGWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Zusy.438036?

Zusy.438036 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment