Malware

Zusy.469316 (file analysis)

Malware Removal

The Zusy.469316 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.469316 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded pe malware family
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Zusy.469316?


File Info:

name: B78207C9C5800E1DA184.mlw
path: /opt/CAPEv2/storage/binaries/db9d71ece4daf1a356062382e894099ad03a7684d222dfe46b46ee102bcb4503
crc32: 2057E6A9
md5: b78207c9c5800e1da1844dd7b31b65dc
sha1: 3c5d3b6007fa0a66fd6d01d71bcfed24706fc7e6
sha256: db9d71ece4daf1a356062382e894099ad03a7684d222dfe46b46ee102bcb4503
sha512: 649bde8479f07071b98a11bf9354fd731f97d320c12d80361f9a0e56fb0c9971c93b88c575ce81ac2219618006420cba0984746a712e8d5ea66d57775ced47f1
ssdeep: 1536:TkuP1P2S9+H8HYiH72PrGGUQLJjk/Jj/9/mck8K1JH:NOS9BHkF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D36402E166D16D15E86BBCBB27F4C0323CA627BE1635402C351B8EE5A2548C1E5FCF92
sha3_384: 356154afc5c989087ef535d35a8faa27efb7bab81021e9143ac21cc1f8118daa4a1ee697dcbc051d0aa6ba8f1542285c
ep_bytes: 68ac114000e8f0ffffff000000000000
timestamp: 2003-06-16 12:34:06

Version Info:

0: [No Data]

Zusy.469316 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.Siggen2.5316
MicroWorld-eScanGen:Variant.Zusy.469316
FireEyeGeneric.mg.b78207c9c5800e1d
CAT-QuickHealWorm.Vobfusd.MF.8301
SkyhighBehavesLike.Win32.VBObfus.ft
ALYacGen:Variant.Zusy.469316
Cylanceunsafe
ZillyaWorm.Vobfus.Win32.1521171
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 001f4fd41 )
AlibabaWorm:Win32/vobfus.1030
K7GWTrojan ( 001f4fd41 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Zusy.D72944
BitDefenderThetaAI:Packer.D9F7D2C71E
VirITTrojan.Win32.X-VBCrypt.EM
SymantecW32.Changeup!gen10
ESET-NOD32a variant of Win32/AutoRun.VB.VE
APEXMalicious
TrendMicro-HouseCallTROJ_AGENT_048732.TOMB
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.djje
BitDefenderGen:Variant.Zusy.469316
NANO-AntivirusTrojan.Win32.VBKrypt.cojaco
AvastWin32:AutoRun-BSB [Wrm]
TencentWorm.Win32.Wbna .16000410
EmsisoftGen:Variant.Zusy.469316 (B)
F-SecureTrojan.TR/Patched.Ren.Gen
BaiduWin32.Worm.VB.al
VIPREGen:Variant.Zusy.469316
TrendMicroTROJ_AGENT_048732.TOMB
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-D
IkarusWorm.Win32.AutoRun
JiangminTrojan/VBKrypt.hcgp
GoogleDetected
AviraTR/Patched.Ren.Gen
VaristW32/Agent.IHS.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
ViRobotTrojan.Win32.A.VBKrypt.299008.CS
ZoneAlarmWorm.Win32.Vobfus.djje
GDataGen:Variant.Zusy.469316
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.VBKrypt.R559158
McAfeeDownloader-CJX.gen.an
VBA32SScope.Trojan.VBRA.75
MalwarebytesGeneric.Worm.AutoRun.DDS
PandaGeneric Malware
RisingWorm.Vobfus!8.10E (TFE:3:mBafMdZEoUH)
YandexTrojan.GenAsa!h406ZqvqTIc
MAXmalware (ai score=80)
MaxSecureTrojan.Malware.6151513.susgen
FortinetW32/AutoRun.VBB!tr
AVGWin32:AutoRun-BSB [Wrm]
DeepInstinctMALICIOUS
alibabacloudWorm:Win/Vobfus.djje

How to remove Zusy.469316?

Zusy.469316 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment