Malware

How to remove “Zusy.520451”?

Malware Removal

The Zusy.520451 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.520451 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.520451?


File Info:

name: 203723D9F1C627AB3483.mlw
path: /opt/CAPEv2/storage/binaries/a6563fd15ce93516917223a4477983ff718acf4beaaa448153d4624809a3a474
crc32: 8FC7E644
md5: 203723d9f1c627ab3483c8c0183b55ec
sha1: aa3909efc4e6a28224020fa636afd238e48d99c4
sha256: a6563fd15ce93516917223a4477983ff718acf4beaaa448153d4624809a3a474
sha512: 3889bf1c04e2df5d0c99fe4f5ed646df665ae29b9d698b48db6b478757384c57aa4134db9b3445afbde72a1a61cb601e18944ab731bb8e3338a143f626b5dfcd
ssdeep: 98304:IMwd0hGyo1IovYiCCpND4h18LovHOFsqISwfOQPXBZrb6sO7WhbD/0nUrvmdbGW:NGp1Io3C24HvuFsqkvb6sO7WhbD8Ur
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T130867C13B2C5403AD0760A3B487A96A5AD3B7A206F1589CB7FFC5B4C0F397816D36687
sha3_384: c41fdfc7dba557f52e0cc3da9b2aa7ee8e97ed10cf2603ae022260865de7f061b20f66ea53d5e8c4f63e03c401ed394c
ep_bytes: 558bec83c4f0b8e41a4f00e834fef0ff
timestamp: 2012-11-14 18:41:07

Version Info:

0: [No Data]

Zusy.520451 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.520451
ClamAVWin.Keylogger.Banbra-9936388-0
ZillyaTrojan.BestaFera.Win32.11029
Cybereasonmalicious.fc4e6a
ArcabitTrojan.Zusy.D7F103
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Zusy.520451
AvastWin32:TrojanX-gen [Trj]
SophosGeneric ML PUA (PUA)
F-SecureTrojan.TR/ATRAPS.Gen
VIPREGen:Variant.Zusy.520451
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.203723d9f1c627ab
EmsisoftGen:Variant.Zusy.520451 (B)
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/ATRAPS.Gen
MAXmalware (ai score=81)
Antiy-AVLGrayWare/Win32.Wacapew
MicrosoftProgram:Win32/Wacapew.C!ml
GDataGen:Variant.Zusy.520451
AhnLab-V3Trojan/Win.Generic.R622629
ALYacGen:Variant.Zusy.520451
Cylanceunsafe
RisingTrojan.Generic@AI.96 (RDML:x2p7/JQpgIsJrGyiuhiHJg)
IkarusTrojan.Win32.Themida
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZelphiCO.36792.@VX@a4bqLfkj
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Zusy.520451?

Zusy.520451 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment