Malware

Zusy.401004 removal guide

Malware Removal

The Zusy.401004 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.401004 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Zusy.401004?


File Info:

name: FB2B2DE3B798E3660B6B.mlw
path: /opt/CAPEv2/storage/binaries/c4e0239fed831a5afaf6b58eb1e178d2d069182bda8601bd817c39eb7a660478
crc32: A31C66F5
md5: fb2b2de3b798e3660b6b3fe76f641e83
sha1: 38dfc94b415ae299b4ebc7a1c0509970b42acc9a
sha256: c4e0239fed831a5afaf6b58eb1e178d2d069182bda8601bd817c39eb7a660478
sha512: 75b5a876c63c3ff902dcf8b2a3d303e07fa37ff4b3bb3d544c5c7ae4a20e763389bd9c03417ce90b7296813c1bebc3c6ab675277d549b302afe8842107b0c6fd
ssdeep: 24576:NHxIygflOmVPl2CRAmWDSy8VclsislVlNd1Cp:NHxIygflOmVPoVmWDSdWlslt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T194A56D8523645458E4EBB6384DAA09EC2D3B7E929820C65F2722FE4D3CF1D48D563B1F
sha3_384: 2cb849d2417e0ca4ad9a8638110f220943d743be7431b15046007da35a06f6decb38627403218dd8016e2e6cbcac6fb7
ep_bytes: 558bec6aff6858b3460068989a460064
timestamp: 2021-09-14 18:37:03

Version Info:

CompanyName: Ashampoo GmbH
FileDescription: Ashampoo ZIP 3
FileVersion: 3.0.26.0
LegalCopyright: Copyright(c) 2019 Ashampoo GmbH
ProductName: Ashampoo ZIP 3
ProductVersion: 3.0
ProgramID: Ashampoo.AshampooZIP
Translation: 0x0409 0x04e4

Zusy.401004 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.401004
FireEyeGeneric.mg.fb2b2de3b798e366
ALYacGen:Variant.Zusy.401004
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
K7AntiVirusTrojan ( 005821bc1 )
K7GWTrojan ( 005821bc1 )
Cybereasonmalicious.b415ae
CyrenW32/Kryptik.FGR.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.HLQM
APEXMalicious
KasperskyUDS:Trojan.Win32.Staser.gen
BitDefenderGen:Variant.Zusy.401004
AvastWin32:CrypterX-gen [Trj]
TencentTrojan.Win32.Staser.za
Ad-AwareGen:Variant.Zusy.401004
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zusy.401004 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.18W14TU
AviraHEUR/AGEN.1244176
MAXmalware (ai score=85)
ArcabitTrojan.Zusy.D61E6C
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R441526
Acronissuspicious
McAfeeGenericRXQB-FZ!FB2B2DE3B798
MalwarebytesAdware.Agent.SFP.Generic
RisingTrojan.Kryptik!1.AA55 (CLASSIC)
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HATU!tr
BitDefenderThetaGen:NN.ZexaF.34742.aA0@aaRRsmgi
AVGWin32:CrypterX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Zusy.401004?

Zusy.401004 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment