Malware

What is “Zusy.402019”?

Malware Removal

The Zusy.402019 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.402019 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with Themida
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Zusy.402019?


File Info:

name: C6F4FC94E7FB3668DD9D.mlw
path: /opt/CAPEv2/storage/binaries/6b95fac782292af0ecc8a4d80d99527239ab61a696c4c6207ecd73787f539c01
crc32: C5615E18
md5: c6f4fc94e7fb3668dd9d6416261d9aba
sha1: 03b33315fde1a08a516cb49454cee930607a86b2
sha256: 6b95fac782292af0ecc8a4d80d99527239ab61a696c4c6207ecd73787f539c01
sha512: 715027ae8d008932f4afe2e107f3a328bc52b7c81d1dad87e08f234688b097f54b0062b200c3c6f463c57b8882469b5842b69c1cb541c63b009b1abafb12ad1d
ssdeep: 98304:6ceFCdcFcH3VY7M/cYqgJEPUYkkJSIb1MjIyYIPWswEqHcnJXdXmmQ5x:aFCdcGVd0YqAEcXkwSwCbHchFmm6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1485633A153A096A5D38AD13F6A14F6ABD04DF7007EDB1C58A8FF1354E9AEE0E23C4750
sha3_384: fbda597ca52fcb8ce42095cf5fc90a5d1af90c309bb67b978d3302422e799203ffde6e69031b24304640e4c26bf66ac6
ep_bytes: e84b0100005389e3538b73088b7b10fc
timestamp: 2022-04-21 11:35:17

Version Info:

0: [No Data]

Zusy.402019 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.402019
CylanceUnsafe
Cybereasonmalicious.5fde1a
ArcabitTrojan.Zusy.D62263
CyrenW32/Zusy.KQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.Themida.CK suspicious
APEXMalicious
BitDefenderGen:Variant.Zusy.402019
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
Ad-AwareGen:Variant.Zusy.402019
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Backdoor.tc
FireEyeGeneric.mg.c6f4fc94e7fb3668
EmsisoftGen:Variant.Zusy.402019 (B)
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Zusy.402019
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R482270
BitDefenderThetaGen:NN.ZexaF.34606.@NW@a8kewEk
ALYacGen:Variant.Zusy.402019
VBA32BScope.Trojan.Wacatac
PandaTrj/Genetic.gen
RisingTrojan.Generic@AI.100 (RDMK:cmRtazoq5Vg8w8qFKi0Dl7eiw0qm)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Zusy.402019?

Zusy.402019 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment