Malware

What is “Zusy.403336”?

Malware Removal

The Zusy.403336 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.403336 virus can do?

  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Zusy.403336?


File Info:

name: 9A20A5D1A414F7E44DB1.mlw
path: /opt/CAPEv2/storage/binaries/634819ce74bd24901e306c2bb6690b2e0774d07de7db6396e1bb7d222f03e0ea
crc32: 801B7BA7
md5: 9a20a5d1a414f7e44db1018be2df6972
sha1: b246bbdb7aac9fc18d5b0df5fefefb0ba7d0da21
sha256: 634819ce74bd24901e306c2bb6690b2e0774d07de7db6396e1bb7d222f03e0ea
sha512: 362b4aa21f169dc2afbeea6d3c79036b6cc7dfa5e5ccef675446279d32845a3cb81fce3d2fbbb943dd16baaca448b08474c673f9e93b0caee76874137ab5544e
ssdeep: 98304:Ta/TPYMPn1ZImprzFO7G7g7CCw80XrvN8o:WTPYMPnRprzY7ze1bvZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A0F5232C4BCB2613C2DBF374BE19BC42B45765E28BE39C7D81EB85D24C7448A4245ABD
sha3_384: ecff1d78aea6d17beb6bc920c429f39b4984d96bc2d7176de377cbc1bdd19e9b04715c7c0c865ea9ee954fa0fa323bae
ep_bytes: 558d6c249881ec0c02000056e9b5f4ff
timestamp: 2021-11-22 19:44:16

Version Info:

0: [No Data]

Zusy.403336 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.403336
FireEyeGeneric.mg.9a20a5d1a414f7e4
CAT-QuickHealTrojan.Wacatac.S15862760
McAfeeGenericRXIP-PX!9A20A5D1A414
CylanceUnsafe
K7AntiVirusTrojan ( 0056cc351 )
K7GWTrojan ( 0056cc351 )
Cybereasonmalicious.1a414f
CyrenW32/S-0cb2f1a4!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GOGM
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.403336
AvastWin32:Evo-gen [Susp]
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazoPMFr1nKDa9MqFQ31XCt6n)
Ad-AwareGen:Variant.Zusy.403336
SophosML/PE-A + Troj/AGent-BFHO
DrWebTrojan.PackedENT.124
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
EmsisoftGen:Variant.Zusy.403336 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1137169
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASBOL.C639
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Zusy.403336
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R346633
BitDefenderThetaGen:NN.ZexaF.34294.ytW@aS2yfsg
ALYacGen:Variant.Zusy.403336
VBA32BScope.Trojan.PackedENT
MalwarebytesTrojan.Crypt.Generic
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_76%
FortinetW32/Kryptik.GOGM!tr
AVGWin32:Evo-gen [Susp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Zusy.403336?

Zusy.403336 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment