Malware

Zusy.535043 (file analysis)

Malware Removal

The Zusy.535043 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.535043 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Zusy.535043?


File Info:

name: 29326409FF84EAD61A5F.mlw
path: /opt/CAPEv2/storage/binaries/b5ec3047edc01570a8d6c28503f8d48f8de61c03b95e94283235694fa57d4f0c
crc32: CC1F39E3
md5: 29326409ff84ead61a5f2e7c3296db56
sha1: 286d4b209e517a680990dbb176103ff81ae3e14f
sha256: b5ec3047edc01570a8d6c28503f8d48f8de61c03b95e94283235694fa57d4f0c
sha512: 10628f8ec1ba599a463bc9d3b718fcebc2a3d0cfe18f1823ac571f25d8d264ff7a8958472be4ba8f0d1a9892dd967d2ebd2ce592b98e60376cfed09d6e5004f8
ssdeep: 768:8xDenyAixbh6zVTCFSxjquEDFAnA1tLRNk2djaYoCMHosTDrEjWD8vJNcW:8xDeni+VKqq2uBNdSCMTrWWYYW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A4435B21B6D28472D6A391B50CF6D290593AFF519B3981DF36E83B250F723C14935F26
sha3_384: 8c844551dad05fdbc682230c8a2c5e4a3d44aebc12cb3ece79391eae8ea1e21e132331db1a19fc734d7c609f5cc3fb88
ep_bytes: e8db130000e989feffff8bff558bec8b
timestamp: 2013-08-27 16:13:37

Version Info:

0: [No Data]

Zusy.535043 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.28161
MicroWorld-eScanGen:Variant.Zusy.535043
ClamAVWin.Malware.Ppatre-6996988-0
FireEyeGeneric.mg.29326409ff84ead6
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.PWSZbot.qh
McAfeePWSZbot-FEV!29326409FF84
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005616531 )
K7GWTrojan ( 005616531 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36744.dyX@aq0LDShk
VirITTrojan.Win32.Crypt2.AXYW
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.BIYN
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.535043
NANO-AntivirusTrojan.Win32.DownLoad3.cjdyni
AvastWin32:Evo-gen [Trj]
TencentTrojan-DL.Win32.Small.hd
EmsisoftGen:Variant.Zusy.535043 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen7
BaiduWin32.Trojan-Spy.Zbot.a
VIPREGen:Variant.Zusy.535043
TrendMicroTROJ_UPATRE.SM37
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.535043
JiangminTrojan/Buzus.bnwn
GoogleDetected
AviraTR/Crypt.XPACK.Gen7
MAXmalware (ai score=80)
Antiy-AVLVirus/Win32.Expiro.ropf
Kingsoftmalware.kb.a.947
XcitiumTrojWare.Win32.TrojanDownloader.Small.PR@5276zr
ArcabitTrojan.Zusy.D82A03
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Fareit.RPL!MTB
VaristW32/RopProof.H.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.C5580656
Acronissuspicious
VBA32Trojan.Fareit.2883
ALYacGen:Variant.Zusy.535043
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.GenAsa!dUSBw1EZjpA
IkarusTrojan-Spy.Win32.Zbot
FortinetW32/Kryptik.BIYN!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.09e517
DeepInstinctMALICIOUS

How to remove Zusy.535043?

Zusy.535043 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment