Malware

Zusy.442987 removal tips

Malware Removal

The Zusy.442987 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.442987 virus can do?

  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.442987?


File Info:

name: 7AAEAA77F3C8D8EFAD01.mlw
path: /opt/CAPEv2/storage/binaries/8ad79bd065e74e9f465d14b686fcf2edd33e67aad5345740b355e65fa72400c7
crc32: B72A4EA1
md5: 7aaeaa77f3c8d8efad013ac4dee54a93
sha1: eb995d9fcd58d5b94191fde0c4fe449a6e4d421a
sha256: 8ad79bd065e74e9f465d14b686fcf2edd33e67aad5345740b355e65fa72400c7
sha512: 30213f61742230ab2319817bf4f88c9565771416da09e4bb6cfb23520bda21b3e52360fc80d0324d662cb2445dd2f84f307d5abea14e92bef020111f27289201
ssdeep: 24576:msOLlPwCgT9WErlVIZzHc/kJkqZE+5ozolSHtn2mKgSNe5FOphi0joI19LQghLeX:mU/kJ/EsS0mK9WOzi0zQ2n210m9zNV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D0B5BE12B181C0B2D129153115B61B39AF74B6524B31EFDBEB98CEA91D33291EF3A34D
sha3_384: ad61124581a497b681587e732a7092406ee2d0e9beb3929cb41311e0a89ff0bbb01abc4baec8e7f71b0b9c2b0530c2fa
ep_bytes: 558bec6aff68a0cd450068780b450064
timestamp: 2022-12-27 00:45:33

Version Info:

0: [No Data]

Zusy.442987 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Blamon.4!c
MicroWorld-eScanGen:Variant.Zusy.442987
ClamAVWin.Dropper.Tiggre-9845940-0
FireEyeGeneric.mg.7aaeaa77f3c8d8ef
CAT-QuickHealHacktool.Flystudio.16558
ALYacGen:Variant.Zusy.442987
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.CoinMiner.Win32.47593
SangforTrojan.Win32.Save.BlackMoon
K7AntiVirusCryptoMiner ( 00593f811 )
AlibabaTrojan:Win32/Blamon.3f7f223e
K7GWCryptoMiner ( 00593f811 )
Cybereasonmalicious.7f3c8d
BitDefenderThetaGen:NN.ZexaF.36350.roW@aKUg2lb
CyrenW32/Coinminer.HG.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/CoinMiner.CIB
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Blamon.gen
BitDefenderGen:Variant.Zusy.442987
NANO-AntivirusTrojan.Win32.Blamon.jugbyb
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10bdbb8c
TACHYONTrojan/W32.Agent.2387968.AR
SophosBlackMoon Packed (PUA)
DrWebTrojan.StartPage1.60936
VIPREGen:Variant.Zusy.442987
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zusy.442987 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1KQMTX4
Antiy-AVLTrojan/Win32.FlyStudio.a
ArcabitTrojan.Zusy.D6C26B
ZoneAlarmHEUR:Trojan.Win32.Blamon.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win.Generic.R546531
Acronissuspicious
VBA32BScope.Trojan.CryptInject
MAXmalware (ai score=81)
Cylanceunsafe
RisingTrojan.CoinMiner!1.E3E0 (CLASSIC)
IkarusTrojan.Win32.CoinMiner
MaxSecureTrojan.Malware.73767576.susgen
FortinetW32/CoinMiner.CIB!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Zusy.442987?

Zusy.442987 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment