Malware

Zusy.535043 (file analysis)

Malware Removal

The Zusy.535043 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.535043 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Zusy.535043?


File Info:

name: AF0BAD2FC4117B59E646.mlw
path: /opt/CAPEv2/storage/binaries/1313280072cb6df4915ef7c7981ddd952c63554f7b5f489168f6b8b505d3fb9c
crc32: 13103892
md5: af0bad2fc4117b59e6469b3ca3b42401
sha1: 5c9a277b5663ecbbc796e927b4832be82a7b4941
sha256: 1313280072cb6df4915ef7c7981ddd952c63554f7b5f489168f6b8b505d3fb9c
sha512: 895fefd47ab27fe6d62d0e7c7b1bec1978392439991b9cb20c0ae1756d3e0237663ace5e93688af5e6faabfe2bd2d66db52bc0e77109c8fc1fdfb29b3df6e84a
ssdeep: 768:tEDE9yDiIbhI6o9Ta4SxjquEDFAnA1tLRNk2djaYoCMHos0ZL9dTbd:tEDE9aW9Hqq2uBNdSCMYdTZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14D435A61F2D18033D4B651781CBAD291593EBF416B3D41DF36A83A6A1F723C18939F2A
sha3_384: 34fff4db08b1bf37d81a26cbf56f172aecf62bb218a6499d3f2f897e645c18a0c44ac1ca92f86b2e1859b2a6071197fe
ep_bytes: e8db130000e989feffff8bff558bec8b
timestamp: 2013-08-27 16:13:37

Version Info:

0: [No Data]

Zusy.535043 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Zusy.535043
FireEyeGeneric.mg.af0bad2fc4117b59
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.qh
McAfeePWSZbot-FEV!AF0BAD2FC411
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Zusy.535043
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005616531 )
K7GWTrojan ( 005616531 )
Cybereasonmalicious.b5663e
BaiduWin32.Trojan-Spy.Zbot.a
VirITTrojan.Win32.Crypt2.AXYW
SymantecDownloader
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BIYN
APEXMalicious
ClamAVWin.Downloader.Upatre-5744092-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.535043
NANO-AntivirusTrojan.Win32.DownLoad3.cjdyni
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
AvastWin32:Evo-gen [Trj]
TencentTrojan-DL.Win32.Small.hd
SophosML/PE-A
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebTrojan.DownLoad3.28161
ZillyaTrojan.Kryptik.Win32.4504084
TrendMicroTROJ_UPATRE.SM37
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zusy.535043 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1DJ5MGL
JiangminTrojan/Buzus.bnwn
GoogleDetected
AviraTR/Crypt.XPACK.Gen7
VaristW32/RopProof.H.gen!Eldorado
Antiy-AVLVirus/Win32.Expiro.ropf
XcitiumTrojWare.Win32.TrojanDownloader.Small.PR@5276zr
ArcabitTrojan.Zusy.D82A03
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Fareit.RPL!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C5580656
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36744.dyX@a41yumek
ALYacGen:Variant.Zusy.535043
MAXmalware (ai score=83)
VBA32Trojan.Fareit.2883
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.GenAsa!dUSBw1EZjpA
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.BIYN!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Zusy.535043?

Zusy.535043 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment