Malware

Zusy.523866 (file analysis)

Malware Removal

The Zusy.523866 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.523866 virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.523866?


File Info:

name: C45939A39D3C7DA020FE.mlw
path: /opt/CAPEv2/storage/binaries/31471e3eb880a5fa2c7915c171fe0166ab9d718fd928d9d6c923dcf454341292
crc32: EAE816ED
md5: c45939a39d3c7da020fe07f2df9e6c6b
sha1: b5f54bc9ff58ed87c44ed6d78de5a9ff36f0c7f7
sha256: 31471e3eb880a5fa2c7915c171fe0166ab9d718fd928d9d6c923dcf454341292
sha512: f394cd8a05fc8f2e36c7f2091c63aaabcb49cf8b687cf4297e573f7e52aa40204c81b7cc5b55671e06edd43b3bc6adcecf8ba62ecaf0cb4c396b64827aeed8c3
ssdeep: 24576:nmXfwc6tUAFTmIRBQwdY8BFCmAc+zynbHSevt8j:nLUAFT3QwdnBFCmkobHrvmj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T107358D12FA9280F6D21619B002FB6735FE34978A0E328F8797ACCD785D727A1963711D
sha3_384: 3c02a2e8c53b3cf454e3fdcba50b2fd652e1e4b77d657909d4330251d85af0fd35527d8948e6ea0beb5ff1c91172826a
ep_bytes: 558bec6aff6828f14d0068e8494a0064
timestamp: 2013-04-17 06:09:32

Version Info:

FileVersion: 2.0.2012.11
FileDescription: ...
ProductName: ...
ProductVersion: 2.0.2012.11
CompanyName: ...
LegalCopyright: ... 版权所有
Comments: ...
Translation: 0x0804 0x04b0

Zusy.523866 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.523866
FireEyeGeneric.mg.c45939a39d3c7da0
CAT-QuickHealRisktool.Flystudio.17324
SkyhighBehavesLike.Win32.Generic.th
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
ArcabitTrojan.Zusy.D7FE5A
BitDefenderThetaGen:NN.ZexaF.36792.br0@am!WqJhb
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/FlyStudio.HackTool.A potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Zusy.523866
AvastWin32:Trojan-gen
EmsisoftGen:Variant.Zusy.523866 (B)
F-SecureTrojan:W32/DelfInject.R
Trapminesuspicious.low.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GoogleDetected
AviraTR/Rootkit.Gen2
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.FlyStudio.a
Kingsoftmalware.kb.a.996
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
MicrosoftTrojan:Win32/Emotet!ml
GDataWin32.Trojan.FlyStudio.I
VaristW32/OnlineGames.HG.gen!Eldorado
Cylanceunsafe
RisingTrojan.Generic@AI.88 (RDML:NNQlIWlxEPyacZPkyhXtHQ)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.PHP!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.9ff58e
DeepInstinctMALICIOUS

How to remove Zusy.523866?

Zusy.523866 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment