Malware

About “Zusy.452805” infection

Malware Removal

The Zusy.452805 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.452805 virus can do?

  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Deletes executed files from disk
  • Anomalous binary characteristics

How to determine Zusy.452805?


File Info:

name: 0B81B1EE8851792AB541.mlw
path: /opt/CAPEv2/storage/binaries/7169a56b4c45d9b130d0e69b85ba6f9d026aba804667d23e29082eb2dd55a371
crc32: 66A60FB7
md5: 0b81b1ee8851792ab54188106e9865b0
sha1: e13d8d9b9c07a6b5008d7a54a4cbd5432e7ff146
sha256: 7169a56b4c45d9b130d0e69b85ba6f9d026aba804667d23e29082eb2dd55a371
sha512: c254ce984cefe7114fcfef340206eb6572d2d97626930477056748d872a1b72467e49c0350dac591077311cd745751ca5fea8b414295ce9638f410dcf437f1cf
ssdeep: 6144:6eHuFUX1p9ykn4RoneYp3kEjiPISUOgW9X+hOGzC/NM:6eHplLyk4R8ZkmZzcukG2/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12C847D07BB8D4363C193077068A765D0A731BDB1BBA687533558724E32B3B745BA33A8
sha3_384: e431f0ce79c8083c8a82d3f706f3694c58754d4263702d2da03013ec419c54da7263d679b87efbfc74b456b7b9d79dcb
ep_bytes: 60be000000008aa60010400080c43580
timestamp: 2007-06-02 06:27:43

Version Info:

CompanyName: TODO:
FileDescription: TODO:
FileVersion: 1.0.0.1
InternalName: AdwTest.exe
LegalCopyright: TODO: (c) . All rights reserved.
OriginalFilename: AdwTest.exe
ProductName: TODO:
ProductVersion: 1.0.0.1
Translation: 0x0409 0x04e4

Zusy.452805 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.452805
ClamAVWin.Malware.Razy-9759519-0
ALYacGen:Variant.Zusy.452805
MalwarebytesGeneric.Trojan.Malicious.DDS
VIPREGen:Variant.Zusy.452805
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004b494b1 )
K7GWTrojan ( 004b494b1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Agent.FRS.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Agent.WTK
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.Nobady.gen
BitDefenderGen:Variant.Zusy.452805
NANO-AntivirusTrojan.Win32.Patched.foubml
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Agent.zl
EmsisoftGen:Variant.Zusy.452805 (B)
F-SecureTrojan.TR/Agent.ietbv
DrWebTrojan.MulDrop5.42246
TrendMicroTROJ_GEN.R03BC0DEK23
McAfee-GW-EditionBehavesLike.Win32.Generic.fm
FireEyeGeneric.mg.0b81b1ee8851792a
SophosMal/Agent-AWE
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.BadJoke.J
AviraTR/Agent.ietbv
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Agent.WTK
XcitiumTrojWare.Win32.Aenjaris.ABC@8hq1l4
ArcabitTrojan.Zusy.D6E8C5
ZoneAlarmTrojan.Win32.Nobady.gen
MicrosoftTrojan:Win32/Aenjaris.AL!bit
GoogleDetected
AhnLab-V3Malware/Win.Generic.C5393361
Acronissuspicious
McAfeeGenericRXOB-DF!0B81B1EE8851
VBA32SScope.Malware-Cryptor.Aenjaris
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DEK23
RisingTrojan.Agent!1.A728 (CLASSIC)
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.WTK!tr
BitDefenderThetaGen:NN.ZexaF.36196.yu3@aqyzW2ki
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.e88517
DeepInstinctMALICIOUS

How to remove Zusy.452805?

Zusy.452805 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment