Malware

Zusy.523942 information

Malware Removal

The Zusy.523942 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.523942 virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.523942?


File Info:

name: EA3A92C2A714AEACAD85.mlw
path: /opt/CAPEv2/storage/binaries/db6b1fd9b39c6891732397e1e8a410883b0ebd4b454d2e23fd5b1c87bed0b6ac
crc32: 5234C28C
md5: ea3a92c2a714aeacad85a5351d65768e
sha1: 5345994fde951e6996a1aeff76e1df5b9f27cae2
sha256: db6b1fd9b39c6891732397e1e8a410883b0ebd4b454d2e23fd5b1c87bed0b6ac
sha512: 86a96940997b219985419d717c7d51b134158e3f2a8d9e4df716a4e18d1ae092aca15cab56dbc8256c0a143fff38daa674b047407bd9c14224e6fd49c1b740d6
ssdeep: 49152:IUBJwUWm+GRFi6JFhWw0/uwEBYkTCtwuXrm:lJjWzWFhYGwEB5utwuXrm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D0D5AE03F6C1C8B3D645157049B717357B32E7622B14DBA3A3A4FDB83E12251AA6B2CD
sha3_384: 93af64e5f3168e4df902b019c669e6e2fe28401d516fca5f72940be0e10d08c2c6dc0351d5b6702317fc0e5ac6a67f36
ep_bytes: 558bec6aff68f85262006894c7520064
timestamp: 2013-03-01 10:19:43

Version Info:

0: [No Data]

Zusy.523942 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.Click2.47487
MicroWorld-eScanGen:Variant.Zusy.523942
FireEyeGeneric.mg.ea3a92c2a714aeac
SkyhighBehavesLike.Win32.Dropper.vm
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Jorik.Win32.213469
CrowdStrikewin/malicious_confidence_90% (D)
ArcabitTrojan.Zusy.D7FEA6
BitDefenderThetaGen:NN.ZexaF.36792.ZsZ@a0Sjyf
VirITTrojan.Win32.Generic.ATVP
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FlyStudio.Injector.A potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Benban-9840578-0
Kasperskynot-a-virus:AdWare.Win32.Agent.gen
BitDefenderGen:Variant.Zusy.523942
NANO-AntivirusTrojan.Win32.Jorik.cchsbw
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.11b90ca5
EmsisoftGen:Variant.Zusy.523942 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen7
BaiduWin32.Trojan.Benban.a
VIPREGen:Variant.Zusy.523942
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Jorik.gnpf
VaristW32/QQhelper.C.gen!Eldorado
AviraTR/Crypt.XPACK.Gen7
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.FlyStudio.a
Kingsoftmalware.kb.a.999
XcitiumWorm.Win32.Dropper.RA@1qraug
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
ZoneAlarmnot-a-virus:AdWare.Win32.Agent.gen
GDataWin32.Trojan.PSE.1CJUYU
GoogleDetected
AhnLab-V3Trojan/Win.Benban.R623792
ALYacGen:Variant.Zusy.523942
VBA32BScope.Trojan.Click
Cylanceunsafe
PandaGeneric Malware
RisingTrojan.Ymacco!8.11BE1 (TFE:5:KfUtn1EfGZP)
YandexTrojan.GenAsa!bthzHOpCEx0
IkarusTrojan.Win32.Benban
MaxSecureTrojan.Kolovorot.in
FortinetW32/CoinMiner.PHP!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.fde951
DeepInstinctMALICIOUS

How to remove Zusy.523942?

Zusy.523942 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment