Malware

Should I remove “Zusy.523406”?

Malware Removal

The Zusy.523406 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.523406 virus can do?

  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.523406?


File Info:

name: EA9ED1C1C3E5F90B8842.mlw
path: /opt/CAPEv2/storage/binaries/9e38d2da7c1ae355541cd310aa8619df0afc0c2cac038b0bf7cf17d0b9bcb979
crc32: 605E325D
md5: ea9ed1c1c3e5f90b8842a167b913701e
sha1: 1af8dd93bbc500079998ad23d671b7874ebc56ff
sha256: 9e38d2da7c1ae355541cd310aa8619df0afc0c2cac038b0bf7cf17d0b9bcb979
sha512: 306caaa41cd97364a803ee3d49543cbb56dcfa1e1dbe79edfdf9709ecdba77a59ccd006c28a5a2bad254a50440775c239efccc13365cfe18578ab31c2e94b8d3
ssdeep: 49152:nfLk6Jjzf8qdwk0cQHGiYYSzSY5voVU7zQYfQP:fLfJjzf8qdwkLQHHhsSYt8qQP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B2850122B5F250F1CA443CF105BAA736EA74AE164A25CFD397A4FDAE3C32580D637119
sha3_384: 996f742852894142c47cd5ecd7f5900595e52fef86db921611fa6a53f1f2bc5101308aeb7ef862ed0f08a95eee151aec
ep_bytes: 558bec6aff6828725900689c2d450064
timestamp: 2013-04-03 13:41:43

Version Info:

FileVersion: 11.1.2011.11
FileDescription: 舞蹈全P辅助
ProductName: QQ飞车舞蹈全P
ProductVersion: 11.1.2011.11
CompanyName: 小伟
LegalCopyright: 小伟制作 切勿盗版
Comments: 混混辅助
Translation: 0x0804 0x04b0

Zusy.523406 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.ltZz
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.523406
FireEyeGeneric.mg.ea9ed1c1c3e5f90b
CAT-QuickHealTrojan.Generic.2919
SkyhighBehavesLike.Win32.Generic.tc
ALYacGen:Variant.Zusy.523406
Cylanceunsafe
SangforTrojan.Win32.Agent.Vkkf
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.3bbc50
ArcabitTrojan.Zusy.D7FC8E
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/FlyStudio.HackTool.A potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Flystudio-9943951-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.523406
AvastWin32:Malware-gen
EmsisoftGen:Variant.Zusy.523406 (B)
F-SecureTrojan:W32/DelfInject.R
VIPREGen:Variant.Zusy.523406
TrendMicroTROJ_GEN.R002C0WKR23
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Blackhole.inr
VaristW32/Trojan.CLL.gen!Eldorado
Antiy-AVLTrojan/Win32.AGeneric
XcitiumWorm.Win32.Dropper.RA@1qraug
MicrosoftPWS:Win32/Zbot!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Application.PSE.1OV7PVV
GoogleDetected
McAfeeArtemis!EA9ED1C1C3E5
MAXmalware (ai score=80)
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallTROJ_GEN.R002C0WKR23
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.GenAsa!JqZpwLvd5bo
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.PHP!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Zusy.523406?

Zusy.523406 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment