Malware

About “Zusy.567” infection

Malware Removal

The Zusy.567 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.567 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Zusy.567?


File Info:

name: B900084D83BB02225C20.mlw
path: /opt/CAPEv2/storage/binaries/79007f060381eaca006e1f39e102b10ccfaa7cda17b83c987521aa6b9b517c3d
crc32: 70260196
md5: b900084d83bb02225c2056bb65ef0754
sha1: 333cded61e4d07297ac3067f49a75215b8f5ec03
sha256: 79007f060381eaca006e1f39e102b10ccfaa7cda17b83c987521aa6b9b517c3d
sha512: 5cbd9b584f6064f91834ae7bc004f4fc3c39edd458fc2a7c001649c0a248d019967087eb34d27f4fdbf97bf8b6ec43f2de92df5f0387aa41d7a80c8147df9874
ssdeep: 6144:t8Ys3FRINO5WcBzjkBP18yAYU7vKd3EUXWidJhKnvmb7/D26XgZKIQ0OfsJy2DJK:tc3fINO5WcBzjkV183Kd3EUXWidJhKnQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BD549462BA18F46AD19388F02D2D9356383E6D760290BC0F7681BF2861B2757B4F475F
sha3_384: 8f9f48e848287900ead5b294d81931d7da736890b01d88806d7352263946d7315ceef5d4fe609a2d6233d12165f693e9
ep_bytes: 6808474000e8eeffffff000040000000
timestamp: 2011-12-28 05:37:27

Version Info:

FileVersion: 1.00
Translation: 0x0409 0x04b0

Zusy.567 also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.WBNA.lxRS
tehtrisGeneric.Malware
DrWebWin32.HLLW.Autoruner2.15227
MicroWorld-eScanGen:Variant.Zusy.567
FireEyeGeneric.mg.b900084d83bb0222
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.dm
McAfeeVBObfus.er
Cylanceunsafe
VIPREGen:Variant.Zusy.567
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
AlibabaWorm:Win32/Vobfus.5f0019b0
K7GWEmailWorm ( 0054d10f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZevbaF.36744.rm0@a0MjzYhi
VirITTrojan.Win32.Zyx.SP
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/AutoRun.VB.AQE
APEXMalicious
CynetMalicious (score: 100)
KasperskyWorm.Win32.Vobfus.dfir
BitDefenderGen:Variant.Zusy.567
NANO-AntivirusTrojan.Win32.Vobfus.chzvjo
TencentMalware.Win32.Gencirc.10be42f7
TACHYONWorm/W32.Vobfus.290816.E
EmsisoftGen:Variant.Zusy.567 (B)
F-SecureWorm.WORM/Vobfus.ommla
BaiduWin32.Worm.Autorun.l
ZillyaTrojan.Diple.Win32.30299
TrendMicroWORM_VOBFUS.SM02
SophosW32/SillyFDC-GT
IkarusWorm.Win32.Vobfus
GDataGen:Variant.Zusy.567
JiangminWorm.Vobfus.gsuk
WebrootW32.Trojan.Diple.Gen
GoogleDetected
AviraWORM/Vobfus.ommla
Antiy-AVLWorm/Win32.WBNA.gen
KingsoftWin32.HeurC.KVM007.a
XcitiumTrojWare.Win32.VB.AVA@4paxk7
ArcabitTrojan.Zusy.567
ViRobotTrojan.Win32.A.Diple.290816.E
ZoneAlarmWorm.Win32.Vobfus.dfir
MicrosoftWorm:Win32/Vobfus!pz
VaristW32/Vobfus.Z.gen!Eldorado
AhnLab-V3Trojan/Win32.Menti.R18663
Acronissuspicious
VBA32BScope.Trojan.Diple
ALYacGen:Variant.Zusy.567
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM02
RisingMalware.FakeFolder/ICON!1.6AA9 (CLASSIC)
YandexTrojan.GenAsa!fODdjQTOEVc
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Diple.EJQE!tr
Cybereasonmalicious.61e4d0
DeepInstinctMALICIOUS

How to remove Zusy.567?

Zusy.567 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment