Malware

About “Zusy.442375” infection

Malware Removal

The Zusy.442375 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.442375 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Zusy.442375?


File Info:

name: 4F495292D83AC653892F.mlw
path: /opt/CAPEv2/storage/binaries/c71fb684626c34648d8b711601d37df3229735610f2711ab1f85cf5aeb48bff1
crc32: 2A17AB2A
md5: 4f495292d83ac653892fb12f42262ea6
sha1: 93ef160ce834eb253c97b233976603892aa3132d
sha256: c71fb684626c34648d8b711601d37df3229735610f2711ab1f85cf5aeb48bff1
sha512: da3a5834e2659baa1c95a8c8862855e2374dc78db12cf60dad7d709497e30ae86e0134f28ce4f604eadf8f361043d44959e04cec0bc03bd01fffe0ef51a6e8ea
ssdeep: 1536:don8Gvl0EIzV2hMqqU+Dn9mNo8OZp8weNZUcD:CnmZBcMqqDT9mNo8wyUcD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BA939D02BBE109A7F0A30BB21AE293263435F4455B7EC64B2444A35E3C673E4AF757D6
sha3_384: cec34be2fe54bc52656ff0bf6c410d05dc92fa87a8948f0203ba7c8c3c27966da59238a1a736b17dd4532c0768b77b03
ep_bytes: 60be00d041008dbe0040feff57eb0b90
timestamp: 2016-04-02 22:14:34

Version Info:

CompanyName: PortableApps.com
LegalCopyright: John T. Haller
LegalTrademarks: Firefox is a Registered Trademark of The Mozilla Foundation. PortableApps.com is a Registered Trademark of Rare Ideas, LLC.
OriginalFilename: FirefoxPortable.exe
Comments: Allows Firefox to be run from a removable drive. For additional details, visit PortableApps.com/FirefoxPortable
FileVersion: 2.0.6.0
ProductName: Mozilla Firefox, Portable Edition
ProductVersion: 2.0.6.0
InternalName: Mozilla Firefox, Portable Edition
FileDescription: Mozilla Firefox, Portable Edition
Created: 7z SFX Constructor v4.5.0.0 (http://usbtor.ru/viewtopic.php?t=798)
Builder: host 03:46:59 16/11/2022
Translation: 0x0000 0x04b0

Zusy.442375 also known as:

LionicRiskware.Win32.Zusy.1!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Zusy.442375
FireEyeGeneric.mg.4f495292d83ac653
McAfeeArtemis!4F495292D83A
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
SymantecML.Attribute.HighConfidence
BitDefenderGen:Variant.Zusy.442375
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Zusy.442375
EmsisoftGen:Variant.Zusy.442375 (B)
VIPREGen:Variant.Zusy.442375
McAfee-GW-EditionArtemis
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Zusy.442375
Antiy-AVLTrojan/Win32.ULPM
ArcabitTrojan.Zusy.D6C007
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R523597
Acronissuspicious
ALYacGen:Variant.Zusy.442375
MAXmalware (ai score=82)
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTROJ_GEN.R002H09KJ22
FortinetW32/ULPM.2C75!tr
AVGWin32:Malware-gen

How to remove Zusy.442375?

Zusy.442375 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment