Malware

Zusy.51399 removal instruction

Malware Removal

The Zusy.51399 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.51399 virus can do?

  • At least one process apparently crashed during execution
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Syriac
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Zusy.51399?


File Info:

name: FCD50EED21AE1084D53B.mlw
path: /opt/CAPEv2/storage/binaries/3d54e32e0116a7e03369e7193e75b329e3ae0482f76bc37950e5d1290f7f0450
crc32: 19E6CA3C
md5: fcd50eed21ae1084d53b3f9d78e714d0
sha1: bb068dce2ffd07b542334632f132fde9fa078633
sha256: 3d54e32e0116a7e03369e7193e75b329e3ae0482f76bc37950e5d1290f7f0450
sha512: e02b8bac1d3f135e070df795085ca0e6e070db1d3f20e5dcb8833484f51f8f6bd90563acea4f7aea69fd2db580821d15d41a7b494811762121e57c0e8e31cdf3
ssdeep: 768:frbIgzi7h6aZLSiDdz6kDQAnHmBNwieN90fXHf3KtjVc5YaDKfT0Owpz9KR1IZNj:PI16aZJ57yCNy/kLXYwv6NDR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A963DA13BA1C41A2D03F5B3014B85B54E73594293B2A43DF1628BE7DEEA13C26F663D9
sha3_384: defdafd0c3436278589d47f3ff5f208dca94f535970161a6bbc57d501ab3a6a1e26ffe9f7004b7de584704bb6683d68e
ep_bytes: e853140000e989feffffcccccccccccc
timestamp: 2013-06-11 20:53:40

Version Info:

Comments: WebMoney. Confidence Internet Information Service Technology.
CompanyName: CJSC "Computing Forces"
FileDescription: WebMoney Keeper Classic Runner Module
FileVersion: 3, 9, 9, 0
InternalName: WebMoney Keeper Classic
LegalCopyright: Copyright © 1998-2012 by CJSC "Computing Forces"
LegalTrademarks: WebMoney Transfer
OriginalFilename: webmoney.exe
ProductName: WebMoney Keeper Classic
ProductVersion: 3, 9, 9, 0
Translation: 0x0419 0x04b0

Zusy.51399 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.51399
FireEyeGeneric.mg.fcd50eed21ae1084
ALYacGen:Variant.Zusy.51399
CylanceUnsafe
ZillyaTrojan.Injector.Win32.398134
SangforTrojan.Win32.Generic.ky
K7AntiVirusTrojan ( 0044e00b1 )
AlibabaTrojan:Win32/Injector.ceebde07
K7GWTrojan ( 0044e00b1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/S-341548bd!Eldorado
SymantecTrojan.Betabot!gm
ESET-NOD32a variant of Win32/Injector.AHZT
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.51399
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Ransom-AXE [Trj]
TencentWin32.Trojan.Generic.Ehrp
Ad-AwareGen:Variant.Zusy.51399
SophosMal/Generic-R + Mal/EncPk-AKA
ComodoMalware@#162omq2zezatt
DrWebTrojan.PWS.Panda.368
VIPRETrojan.Win32.Reveton.a (v)
TrendMicroTROJ_GEN.R002C0PB922
McAfee-GW-EditionPWS-Zbot-FAXY!FCD50EED21AE
EmsisoftGen:Variant.Zusy.51399 (B)
GDataGen:Variant.Zusy.51399
JiangminTrojan.Generic.cbzfo
WebrootW32.Rogue.Gen
AviraHEUR/AGEN.1213667
Antiy-AVLTrojan[Ransom]/Win32.Foreign
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Occamy.sa
ArcabitTrojan.Zusy.DC8C7
ViRobotTrojan.Win32.Z.Zusy.71168.EH
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Occamy.C3D
CynetMalicious (score: 100)
McAfeePWS-Zbot-FAXY!FCD50EED21AE
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.Panda
TrendMicro-HouseCallTROJ_GEN.R002C0PB922
RisingTrojan.Injector!8.C4 (CLOUD)
YandexTrojan.GenAsa!qSmiCBT3f0Q
IkarusTrojan.Win32.Loktrom
eGambitGeneric.Malware
FortinetW32/Crypt.PFO!tr
BitDefenderThetaGen:NN.ZexaF.34232.eu0@aqzfneiI
AVGWin32:Ransom-AXE [Trj]
PandaTrj/Genetic.gen

How to remove Zusy.51399?

Zusy.51399 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment