Malware

Zusy.467825 (B) removal guide

Malware Removal

The Zusy.467825 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.467825 (B) virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Zusy.467825 (B)?


File Info:

name: C5E2D020CF3597BA731C.mlw
path: /opt/CAPEv2/storage/binaries/786dc3695859ed2c55e6dad8a683d26c38c11bae53c2967146c30ffeb020adbb
crc32: 2624DB79
md5: c5e2d020cf3597ba731c62d29e6c02d1
sha1: fcb276eaf23ade880a6fdfbb7f22fccdcbf92fe9
sha256: 786dc3695859ed2c55e6dad8a683d26c38c11bae53c2967146c30ffeb020adbb
sha512: 33859e50c6a04c4447c941a9355fb1cc17400fc25752e03a0f1c9c812a72c6b2945c30ddee70b08e1739503cb9b70ec6bfe256df4696905a8b9899314077ae65
ssdeep: 1536:ki0MjgqtFyWQ5i+u1ISCLTN4BDzhBPpsJ6/eLuJORYM:kssNLTNHRYM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16BA3F7D6FAD5ADA7DA09063E89EA8319233DF6D80B838B034E3875341B575D06ED3247
sha3_384: 8b4b30ba9822c6bc113f8200a93910ec9d4bd57e9b846e12e1da8d3c23e69830227bb5edeecd5b344e2063c935f42892
ep_bytes: c7056460400001000000e971fdffff90
timestamp: 2024-04-03 03:57:16

Version Info:

0: [No Data]

Zusy.467825 (B) also known as:

LionicTrojan.Win32.Generic.mfqG
MicroWorld-eScanGen:Variant.Zusy.467825
FireEyeGeneric.mg.c5e2d020cf3597ba
SkyhighBehavesLike.Win32.Generic.cm
ALYacGen:Variant.Zusy.467825
Cylanceunsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36802.g8Y@a8DbT0i
VirITTrojan.Win32.Genus.UXL
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent.QQQ
APEXMalicious
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.467825
NANO-AntivirusTrojan.Win32.Mlw.kbfjju
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Generic.Qqil
SophosATK/Veil-B
GoogleDetected
F-SecureTrojan.TR/ATRAPS.Gen7
VIPREGen:Variant.Zusy.467825
EmsisoftGen:Variant.Zusy.467825 (B)
IkarusTrojan.Win32.Rozena
VaristW32/Veil.D.gen!Eldorado
AviraTR/ATRAPS.Gen7
Antiy-AVLTrojan/Win32.Veil
Kingsoftmalware.kb.a.962
MicrosoftTrojan:Win32/Leivion.L
ArcabitTrojan.Zusy.D72371
ZoneAlarmUDS:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.12QCQ5P
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R596585
Acronissuspicious
McAfeeArtemis!C5E2D020CF35
MAXmalware (ai score=83)
VBA32BScope.Trojan.Click
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingTrojan.Agent!8.B1E (TFE:5:X0VVjO6EgmQ)
SentinelOneStatic AI – Malicious PE
FortinetW32/Veilev.E!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.0cf359
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Leivion.L

How to remove Zusy.467825 (B)?

Zusy.467825 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment