Malware

Zusy.534081 malicious file

Malware Removal

The Zusy.534081 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.534081 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • CAPE detected the embedded win api malware family
  • Attempts to disable Windows Auto Updates
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Zusy.534081?


File Info:

name: 91C790A76FBA3807E6B1.mlw
path: /opt/CAPEv2/storage/binaries/38d0c21214cb128c41cdeaecb7273f6e7d01592416aecacf24bf6ca919d1eaf0
crc32: C8941828
md5: 91c790a76fba3807e6b1fab2fb3adace
sha1: f9a3f3f465f95c930b51d4a74a616e1675e59487
sha256: 38d0c21214cb128c41cdeaecb7273f6e7d01592416aecacf24bf6ca919d1eaf0
sha512: 72746ad340b7274c8a4513dea388df54d0f6c761d98be0f5d6133ab8ac7776cc0d8e78b6b2645426725b2320b81fdd6e1906d2e4e6449e096cfc1f2518f4bfcd
ssdeep: 3072:m0bfWRrIMNRlZ62Pal2LBJXmzOHm5WZ3K+MCXdOQ39cOaRr5ZGPV:mWepp3PJXCOGY3e8OQ39c
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T197846B7FB746A471C626713923F2C7AA05BB66499D03004F6A183BE90CB3F145CADAD7
sha3_384: 4ddc132ef362c4e24da5d937ded8a4cdc8dc727a7b128c8b57b423bd30700b2a7c880c597c4ebe902b398a44ed29e54a
ep_bytes: 6810134000e8f0ffffff000060000000
timestamp: 1996-08-20 19:21:28

Version Info:

0: [No Data]

Zusy.534081 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.534081
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.fm
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (D)
K7GWEmailWorm ( 003c363a1 )
K7AntiVirusEmailWorm ( 003c363a1 )
BaiduWin32.Worm.Pronny.fm
VirITTrojan.Win32.VBCrypt.EWG
SymantecW32.Changeup!gen20
ESET-NOD32Win32/Pronny.CS
APEXMalicious
TrendMicro-HouseCallTROJ_AGENT_048703.TOMB
ClamAVWin.Trojan.VB-1623
KasperskyTrojan.Win32.Vobfus.ykz
BitDefenderGen:Variant.Zusy.534081
NANO-AntivirusTrojan.Win32.Symmi.cfdsmv
AvastWin32:VB-AEEX [Trj]
TACHYONTrojan/W32.VB-Vobfus.393216
EmsisoftGen:Variant.Zusy.534081 (B)
F-SecureTrojan.TR/Symmi.AJ.1
DrWebTrojan.DownLoader6.46525
VIPREGen:Variant.Zusy.534081
TrendMicroTROJ_AGENT_048703.TOMB
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.91c790a76fba3807
SophosMal/VBCheMan-J
IkarusWorm.Win32.Vobfus
JiangminTrojan/Jorik.ggsi
WebrootW32.Obfuscated.Gen
GoogleDetected
AviraTR/Symmi.AJ.1
VaristW32/VB.HE.gen!Eldorado
Antiy-AVLWorm/Win32.WBNA.gen
MicrosoftWorm:Win32/Vobfus!pz
ArcabitTrojan.Zusy.D82641
ZoneAlarmTrojan.Win32.Vobfus.ykz
GDataWin32.Trojan.VB.GX
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Vobfus.R632105
Acronissuspicious
VBA32TScope.Trojan.VB
ALYacGen:Variant.Zusy.534081
MAXmalware (ai score=80)
Cylanceunsafe
PandaTrj/Genetic.gen
RisingWorm.Pronny!1.E3E7 (CLASSIC)
YandexTrojan.GenAsa!BJNHdllNgE0
SentinelOneStatic AI – Malicious PE
FortinetW32/VBObfus.AU!tr
BitDefenderThetaGen:NN.ZevbaF.36802.yuZ@a4aDTjh
AVGWin32:VB-AEEX [Trj]
Cybereasonmalicious.76fba3
DeepInstinctMALICIOUS

How to remove Zusy.534081?

Zusy.534081 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment