Malware

Zusy.9250 removal instruction

Malware Removal

The Zusy.9250 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.9250 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Zusy.9250?


File Info:

crc32: F837E62D
md5: 8117bfec08fa084358e994974b71aa3e
name: 8117BFEC08FA084358E994974B71AA3E.mlw
sha1: 08b09a12524a0ec4933b991292b60d06634b4780
sha256: dbc1f6d2192dd6a3e3daaacda046317929bdbf6ec922f554aa356ad7871d7ed0
sha512: ef3f4521870eb608ba165b09cf8a95cdc1e27936a15fb4b6b7a4589f86b7e18b61f01be796fc377b7160a684b106559b7636aeb74b1bf57e9c3911480740a48e
ssdeep: 1536:T53hV6TIb8cnaDwdqZJE2cuOb5neTbTJcY0CssfwK9sDgw/0infveTI5nIP:TrYI+Mt2cb5nG3ssfwK9sDljuI5n
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: 0
FileVersion: 1.02.0002
CompanyName: Avira
Comments: Dmar
ProductName: Dm4r
ProductVersion: 1.02.0002
OriginalFilename: 0.exe

Zusy.9250 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.9250
FireEyeGeneric.mg.8117bfec08fa0843
CAT-QuickHealTrojan.VBKrypt
McAfeeGeneric VB.fl
CylanceUnsafe
ZillyaDropper.VB.Win32.39675
SangforMalware
K7AntiVirusTrojan ( 00570c1d1 )
BitDefenderGen:Variant.Zusy.9250
K7GWTrojan ( 00570c1d1 )
Cybereasonmalicious.c08fa0
BitDefenderThetaAI:Packer.9D0E0A0320
CyrenW32/VBInject.AH.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.BLTE
APEXMalicious
AvastWin32:GenMalicious-KJI [Trj]
CynetMalicious (score: 100)
KasperskyTrojan.Win32.VBKrypt.wlmz
AlibabaTrojan:Win32/VBKrypt.d579fa7b
NANO-AntivirusTrojan.Win32.VB.hnyqc
RisingHackTool.VBInject!1.6482 (CLASSIC)
Ad-AwareGen:Variant.Zusy.9250
SophosML/PE-A + Mal/SpyEye-L
ComodoTrojWare.Win32.Injector.dec@4mpx5r
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.Inject.54861
VIPRETrojan.Win32.Vbinject.mzob (v)
TrendMicroCryp_SpyEye
McAfee-GW-EditionGeneric VB.fl
EmsisoftGen:Variant.Zusy.9250 (B)
IkarusTrojan.Win32.Zmunik
JiangminTrojan.VBKrypt.bbok
AviraTR/Dropper.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.VBKrypt
MicrosoftVirTool:Win32/VBInject.UG
ArcabitTrojan.Zusy.D2422
AhnLab-V3Dropper/Win32.VB.R19239
ZoneAlarmTrojan.Win32.VBKrypt.wlmz
GDataGen:Variant.Zusy.9250
TotalDefenseWin32/VBInject.Z!generic
ALYacGen:Variant.Zusy.9250
VBA32Malware-Cryptor.VB.Sazeka
MalwarebytesGeneric.Trojan.Dropper.DDS
PandaGeneric Malware
TencentWin32.Trojan.Vbkrypt.Dwix
YandexTrojan.GenAsa!7u3wIo7E+3o
SentinelOneStatic AI – Suspicious PE
FortinetW32/Bifrose.NKY!tr
WebrootW32.Injector.Gen
AVGWin32:GenMalicious-KJI [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM03.0.3C5B.Malware.Gen

How to remove Zusy.9250?

Zusy.9250 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment