Malware

Zusy.535043 (B) removal guide

Malware Removal

The Zusy.535043 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.535043 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Zusy.535043 (B)?


File Info:

name: 10C7CB464F21588BB429.mlw
path: /opt/CAPEv2/storage/binaries/f0a560c72cbd71c999ee07897c056ad3966e6e7e7612a281ee0400297b5f7992
crc32: 1397BC6F
md5: 10c7cb464f21588bb4292c5256f11149
sha1: 667a6aa728e97e8bb533a066ee7b4b576ef8de18
sha256: f0a560c72cbd71c999ee07897c056ad3966e6e7e7612a281ee0400297b5f7992
sha512: 5259a8176bf47fb5de2f9679d6d44eced6a97f4ad2085d1475f8aa421fd41a4491430ea6c9bd10ad2d5c570df040f82241a9559b25689872cf0ab815223b91b1
ssdeep: 768:Xiw6nLAiObhneoJTlUSSxjquEDFAnA1tLRNk2djaYoCMHosSDQCnBIR:Xiw6n8VJhfqq2uBNdSCMaQDR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13D435A21B6D18033D4B351781CB9D291693ABF416B3C40DF37A83A6A5F723C19979F2A
sha3_384: a28dedfbbc850b761043da1a7d07b0f104e204873806f849ad6ee9f56690d9b6f7574ae50c9a80f3534ebcfe30bdad84
ep_bytes: e8db130000e989feffff8bff558bec8b
timestamp: 2013-08-27 16:13:37

Version Info:

0: [No Data]

Zusy.535043 (B) also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.28161
MicroWorld-eScanGen:Variant.Zusy.535043
ClamAVWin.Downloader.Upatre-5744087-0
FireEyeGeneric.mg.10c7cb464f21588b
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.qh
McAfeePWSZbot-FEV!10C7CB464F21
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.4593411
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005616531 )
AlibabaTrojan:Win32/Kryptik.05563ddf
K7GWTrojan ( 005616531 )
BitDefenderThetaGen:NN.ZexaF.36804.dyX@au2QwXpk
VirITTrojan.Win32.Crypt2.AXYW
SymantecDownloader
ESET-NOD32a variant of Win32/Kryptik.BIYN
TrendMicro-HouseCallTROJ_UPATRE.SM37
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.535043
NANO-AntivirusTrojan.Win32.DownLoad3.cjdyni
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
AvastWin32:Evo-gen [Trj]
TencentTrojan-DL.Win32.Small.hd
EmsisoftGen:Variant.Zusy.535043 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen7
BaiduWin32.Trojan-Spy.Zbot.a
VIPREGen:Variant.Zusy.535043
TrendMicroTROJ_UPATRE.SM37
SentinelOneStatic AI – Malicious PE
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan-Spy.Win32.Zbot
JiangminTrojan/Buzus.bnwn
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLVirus/Win32.Expiro.ropf
KingsoftWin32.Trojan.Generic.a
XcitiumTrojWare.Win32.TrojanDownloader.Small.PR@5276zr
ArcabitTrojan.Zusy.D82A03
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.1EIAX66
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R639496
Acronissuspicious
ALYacGen:Variant.Zusy.535043
MAXmalware (ai score=80)
VBA32Trojan.Fareit.2883
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
APEXMalicious
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.GenAsa!dUSBw1EZjpA
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.BIYN!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[downloader]:Win/Injector.AMYE

How to remove Zusy.535043 (B)?

Zusy.535043 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment