Malware

Zusy.469390 removal instruction

Malware Removal

The Zusy.469390 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.469390 virus can do?

  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Binary compilation timestomping detected

How to determine Zusy.469390?


File Info:

name: A14EFD3CCFE5C843DB0F.mlw
path: /opt/CAPEv2/storage/binaries/8433170b54ef6ff580a95b547d10b8dba98c8f4a993419b6c012159ae9463a30
crc32: 3E9D3CEB
md5: a14efd3ccfe5c843db0f4931bf75797a
sha1: a6e96bbe233ffa99ad9b37e71964ae34a9bf3fde
sha256: 8433170b54ef6ff580a95b547d10b8dba98c8f4a993419b6c012159ae9463a30
sha512: 08291af851887578d1b5be5e8265409bb013b68629c774b66016f450e43888d6eda0dd293de39e25aad4cf0205cb225788bee959f893fb87fb6f7916cdd17d34
ssdeep: 384:ZgsbFllCbjNhaiwGQAxRr6+09PfL3vYTQzRssMSvhR8:ZVF3C1haiwGbx8v7fYTQzRssMmP8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T168B2E6225B8DBDE4E2CE29351939B2118675E56843E04BDF4FA025EE6C320D3FC3665B
sha3_384: 3c05a8fd4158efa04304e7f1a1da65d1b6fb996b0bec13732aed311d1a436189c1a8bd8c50945f853789ab6e57cb580a
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2071-10-08 19:21:25

Version Info:

CompanyName: HujVabBin
FileDescription: HujVabBin Inc.
FileVersion: Version 1.18
InternalName: HujVabBin
LegalCopyright: Copyright by HujVabBin Inc.
OriginalFilename: HujVabBin
Translation: 0x0408 0x04e2

Zusy.469390 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Upatre.1j!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.469390
ClamAVWin.Downloader.Upatre-10004442-0
SkyhighBehavesLike.Win32.Generic.mm
McAfeeGenericRXVF-TM!A14EFD3CCFE5
MalwarebytesWaski.Trojan.Downloader.DDS
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005aa5ef1 )
K7GWTrojan ( 005aa5ef1 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent_AGen.BOK
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Downloader.Win32.Upatre.jjpi
BitDefenderGen:Variant.Zusy.469390
SUPERAntiSpywareTrojan.Agent/Gen-FalComp
AvastWin32:Upatre-E [Trj]
TencentWin32.Trojan-Downloader.Upatre.Iajl
EmsisoftGen:Variant.Zusy.469390 (B)
F-SecureHeuristic.HEUR/AGEN.1366239
DrWebTrojan.Upatre.87
VIPREGen:Variant.Zusy.469390
TrendMicroTROJ_GEN.R03BC0DB824
FireEyeGeneric.mg.a14efd3ccfe5c843
SophosMal/EncPk-ADE
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.469390
JiangminTrojan.GenericML.vg
WebrootTrojan.Dropper.Gen
GoogleDetected
AviraHEUR/AGEN.1366239
MAXmalware (ai score=81)
Kingsoftmalware.kb.a.1000
GridinsoftTrojan.Win32.Downloader.sa
XcitiumTrojWare.Win32.TrojanDownloader.Agent.AVL@5geo8n
ArcabitTrojan.Zusy.D7298E
ZoneAlarmTrojan-Downloader.Win32.Upatre.jjpi
MicrosoftTrojanDownloader:Win32/Upatre.AA
VaristW32/Upatre.HB.gen!Eldorado
AhnLab-V3Malware/Win32.Generic.C2800625
Acronissuspicious
ALYacGen:Variant.Zusy.469390
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R03BC0DB824
RisingDownloader.Upatre!8.B5 (CLOUD)
IkarusTrojan-Downloader.Win32.Upatre
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Upatre.E!tr
BitDefenderThetaGen:NN.ZexaF.36744.bu0@aGivAtjG
AVGWin32:Upatre-E [Trj]
Cybereasonmalicious.e233ff
DeepInstinctMALICIOUS

How to remove Zusy.469390?

Zusy.469390 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment