Malware

What is “Zusy.211601”?

Malware Removal

The Zusy.211601 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.211601 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • .NET file is packed/obfuscated with Confuser
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Zusy.211601?


File Info:

name: 2FC50D5063DD842DF782.mlw
path: /opt/CAPEv2/storage/binaries/c61722c0a2dfc90f0a05f5db73fad06108a02a672972253371de277c06af1476
crc32: B5555870
md5: 2fc50d5063dd842df78242cb801dc2da
sha1: bd3cd11b3ff1814c5793b66ecc45fb12f364cb8e
sha256: c61722c0a2dfc90f0a05f5db73fad06108a02a672972253371de277c06af1476
sha512: 8fa2d75c9c5b76109a1af70396158fa00eaa16f64e88a53d412a864907363053cd8372c6df866353dcd2e586d8e10f804f17574f5c9ceeeaa6df0931fcfdd155
ssdeep: 384:QKVn01TYL1bYsFvEqQ4iDtwYFP53igjjEsggcGgIkKzsW7DfCZByh4WA2oW:ln01q0sF9WwYFP8w3cGgKD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T123C2AF41ABCCD823E3DA077CD583D6050BB2BB265056E3CF7C8122A54E9E3D286173A3
sha3_384: 4a1f310669b944aa242a6a8674f7a08b99b00e5cf4cae6b6daa15a723449b418439fc449b0a6db7232a6cc7c611019ad
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-03-17 06:59:22

Version Info:

CompanyName: Microsoft Corporation
FileDescription: COM Surrogate
FileVersion: 10.0.18362.1 (WinBuild.160101.0800)
InternalName: dllhost.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: dllhost.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.18362.1
Translation: 0x0409 0x04b0

Zusy.211601 also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.211601
McAfeeTrojan-FSCL!2FC50D5063DD
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004915961 )
K7GWTrojan ( 004915961 )
Cybereasonmalicious.063dd8
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Bladabindi.AS
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.211601
AvastMSIL:GenMalicious-BIU [Trj]
TencentWin32.Trojan.Generic.Hwdh
Ad-AwareGen:Variant.Zusy.211601
EmsisoftGen:Variant.Zusy.211601 (B)
ZillyaTrojan.Generic.Win32.1398234
McAfee-GW-EditionBehavesLike.Win32.Generic.mc
FireEyeGeneric.mg.2fc50d5063dd842d
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.211601
MicrosoftBackdoor:Win32/Bladabindi!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Crypt.C4015899
Acronissuspicious
ALYacGen:Variant.Zusy.211601
MAXmalware (ai score=80)
MalwarebytesMalware.AI.1384190261
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL:/QKGWEq9fT9yfth5PvYNYA)
YandexTrojan.Agent!eNSxrn/yynE
IkarusTrojan.MSIL.Bladabindi
MaxSecureTrojan.Malware.7164915.susgen
FortinetMSIL/GenKryptik.CRCM!tr
BitDefenderThetaGen:NN.ZemsilF.34638.bm0@a0rhEvpi
AVGMSIL:GenMalicious-BIU [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Zusy.211601?

Zusy.211601 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment