Malware

Zusy.522627 information

Malware Removal

The Zusy.522627 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.522627 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.522627?


File Info:

name: 2A981DC2744C1EFE4C97.mlw
path: /opt/CAPEv2/storage/binaries/2d7993ff59da1117687fac6c1dc195dfbf244cf10be1181cb152dba2ef480c19
crc32: 29A7F739
md5: 2a981dc2744c1efe4c973e698400dbaf
sha1: cbdb1d3350c9f61a19b3bc2e03eab47dd1a58077
sha256: 2d7993ff59da1117687fac6c1dc195dfbf244cf10be1181cb152dba2ef480c19
sha512: cb31bb773a42e6ff13c935cd63ba5856813f852c27984f1e25f8c73992e176e5ac5fda6a4ceb476f43c2baa28eb5abd4e5d0224c0ec515d6d59ba5fc7d463fba
ssdeep: 98304:jMjUKQyK5kMuj3aDrW3u+YBX4hxTk60I4dFCf1rx8YXJ290Kp5l:jMwKQKMu7aKYaT33drx8QMl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16B26335197051F85CE10F9F407C7B2DD7C96729415A2E3EB0AA33348E2E4B9878BBB94
sha3_384: 8285e1850663240aea2ca459ef0eb95c0454c5108579357fba77a9d56f3c52b0579c0555976dfccc295c91da0b713d11
ep_bytes: b840653c015064ff3500000000648925
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName:
FileDescription: 巨牛CD登录器
FileVersion: 1.7.5.7
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments: www.jndlq.com
Translation: 0x0804 0x03a8

Zusy.522627 also known as:

MicroWorld-eScanGen:Variant.Zusy.522627
SkyhighGenericRXUK-GX!B0A9CEF2558F
McAfeeGenericRXUK-GX!B0A9CEF2558F
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.350c9f
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.MultiPacked.BN
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Tedy-10014624-0
BitDefenderGen:Variant.Zusy.522627
NANO-AntivirusTrojan.Win32.Crypted.doiilj
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.13f646de
SophosMal/Packer
F-SecureHeuristic.HEUR/AGEN.1350194
FireEyeGeneric.mg.2a981dc2744c1efe
AviraHEUR/AGEN.1350194
MAXmalware (ai score=83)
Antiy-AVLTrojan/Win32.SGeneric
Kingsoftmalware.kb.a.905
MicrosoftProgram:Win32/Wacapew.C!ml
GDataGen:Variant.Zusy.522627
GoogleDetected
VBA32suspected of Trojan.Downloader.gen
Cylanceunsafe
IkarusBackdoor.Win32.Hupigon
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove Zusy.522627?

Zusy.522627 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment