Malware

What is “Ser.Zusy.4059”?

Malware Removal

The Ser.Zusy.4059 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Zusy.4059 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Ser.Zusy.4059?


File Info:

name: 09F95CCFBDBB9AE0BB26.mlw
path: /opt/CAPEv2/storage/binaries/24ead2beb28f6cc1cb016b96d2ecf1ea81087f54999c9a0cb75d645a795ccde7
crc32: 4EBD5CB9
md5: 09f95ccfbdbb9ae0bb265ae28dcdf52a
sha1: c36799ae3e79be886ae688efef4394c2ae802a51
sha256: 24ead2beb28f6cc1cb016b96d2ecf1ea81087f54999c9a0cb75d645a795ccde7
sha512: 65d0c50665ae9ca9df92a3e20a694869af9d9d6da829345a7251593a516b9ad27c3d397eabdce2002b24ab43b3ee06de916caf64e32c36b01408095d18a2769d
ssdeep: 6144:Jd8iQOmjk0rJme93AO8k9g5LQAtY0vic:xQTjD/ul5LQAq8i
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F4555CCAE44FA0A3DA993B3B3CD8475CB92C532206FCA7D65E47C7E527123815A2CD25
sha3_384: ff7d7b606595645c40be1fd2e4f919f191332d5165095cc7ac8163a9e96cfd883b390bece0e50e466371c19fa689e114
ep_bytes: e810040000e974feffff3b0d14a04200
timestamp: 2023-03-04 05:04:13

Version Info:

0: [No Data]

Ser.Zusy.4059 also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ser.Zusy.4059
ALYacGen:Variant.Ser.Zusy.4059
Cylanceunsafe
SangforTrojan.Win32.Save.a
Cybereasonmalicious.e3e79b
BitDefenderThetaGen:NN.ZexaF.36308.ovW@aqUpsOj
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HSQQ
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Exploit.Win32.Agent.gen
BitDefenderGen:Variant.Ser.Zusy.4059
AvastWin32:PWSX-gen [Trj]
RisingExploit.Agent!8.1B (TFE:5:9J8VvHcT0XH)
EmsisoftGen:Variant.Ser.Zusy.4059 (B)
DrWebTrojan.PWS.Steam.34510
VIPREGen:Variant.Ser.Zusy.4059
McAfee-GW-EditionBehavesLike.Win32.Generic.tz
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.09f95ccfbdbb9ae0
SophosML/PE-A
IkarusTrojan.Win32.Crypt
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Ser.Zusy.DFDB
ZoneAlarmHEUR:Exploit.Win32.Agent.gen
GDataGen:Variant.Ser.Zusy.4059
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R560814
Acronissuspicious
McAfeeGenericRXVN-LF!09F95CCFBDBB
MAXmalware (ai score=80)
TencentMalware.Win32.Gencirc.10be3276
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HSIR!tr
AVGWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Ser.Zusy.4059?

Ser.Zusy.4059 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment