Malware

What is “Zusy.522112”?

Malware Removal

The Zusy.522112 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.522112 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.522112?


File Info:

name: D1930A60F3F53782E6EC.mlw
path: /opt/CAPEv2/storage/binaries/079c636d373845d0896c8d69718cff6dfe546c9f1582cd4a7b765e0f3aea5080
crc32: 5DC493B6
md5: d1930a60f3f53782e6ec925fef0126c2
sha1: eea2e7ec16478eb4b809670f89514bc51d3e2c11
sha256: 079c636d373845d0896c8d69718cff6dfe546c9f1582cd4a7b765e0f3aea5080
sha512: cbcda79beaf01405b76ba61da84f696af13d0221f4a4bac9ea824e1e4433663b28d05a46c9f04a752309e3698b91a7a67043ef94d49233dbf05b3adda9d751d8
ssdeep: 24576:AhJJPq65ZmMdKBeiJ2Y8907NXK/ELm40mi0NXF5NXhhMRmRf+mjYvTJnhiy9RUt+:Er+XZRflQpP8vi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AA857D23F642C0F2C210257265BA2B756E78DB651E39CAE3A394DDB45D31170AB3F21E
sha3_384: 7f0b140eba3cb2f9429d6302487f677ffb0abfc68e5d7136bef1f4ce32f91eebc488f6aab53563e39ca94d411ff2f5a1
ep_bytes: 558bec6aff6810c85600681804520064
timestamp: 2023-12-30 12:25:39

Version Info:

FileVersion: 14.1.1205.0
FileDescription: 360安全浏览器
ProductName: 360安全浏览器
ProductVersion: 14.1.1205.0
CompanyName: 360.cn
LegalCopyright: 360.cn 版权所有
Comments: 360安全浏览器
Translation: 0x0804 0x04b0

Zusy.522112 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lqqA
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.522112
FireEyeGeneric.mg.d1930a60f3f53782
SkyhighBehavesLike.Win32.Generic.th
McAfeeArtemis!D1930A60F3F5
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
AlibabaTrojan:Win32/Generic.c2c5aab3
Cybereasonmalicious.c16478
ArcabitTrojan.Zusy.D7F780
BitDefenderThetaGen:NN.ZexaE.36608.Qr0@aWrQxfbb
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
KasperskyUDS:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.522112
AvastWin32:TrojanX-gen [Trj]
EmsisoftGen:Variant.Zusy.522112 (B)
VIPREGen:Variant.Zusy.522112
Trapminemalicious.high.ml.score
SophosGeneric Reputation PUA (PUA)
IkarusTrojan.Win32.Agent
WebrootW32.Trojan.Kazy
VaristW32/Trojan.CLL.gen!Eldorado
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumWorm.Win32.Dropper.RA@1qraug
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmUDS:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.1KQMTX4
GoogleDetected
AhnLab-V3Trojan/Win.TrojanX-gen.R629093
ALYacGen:Variant.Zusy.522112
MAXmalware (ai score=81)
MalwarebytesGeneric.Malware.AI.DDS
RisingTrojan.Generic@AI.100 (RDML:YqskWennnq8oT5d1Tpq/Ig)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Zusy.522112?

Zusy.522112 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment