Malware

How to remove “Zusy.403365”?

Malware Removal

The Zusy.403365 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.403365 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Zusy.403365?


File Info:

name: 8D1C723A603A0A972C11.mlw
path: /opt/CAPEv2/storage/binaries/c024b37aebb1bfd7c5e9008c162bf5c333c643b160ec76f8ff46bdb879a22519
crc32: 99BBD010
md5: 8d1c723a603a0a972c11d51230679a69
sha1: a57bf60e598f8ff909c439c15ee05ea013159ca5
sha256: c024b37aebb1bfd7c5e9008c162bf5c333c643b160ec76f8ff46bdb879a22519
sha512: 76d6d581e1d0cb9e565b8a93f2bc7188f69d4f5bbffc389026776519b623d9534f5374c57c3e7887b5554aac5fdeba8df742a4c2c188a1b97a704cdae643f3aa
ssdeep: 98304:Q8DysdsbpqEZQA8I4s4ApkUQvF3gaHD0krf8:Q8DysdsbpqEeymlh3gmD0s0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15C36BE1D7373E623C19A1575D92A08F478326FF0E8D3846BB2AC7C8D3BB4449962935E
sha3_384: 9e5f63026fba7133858fc7395dda692733c03cd5ae7abd8d5c79af5150c35b3a3f0a9400d871ca90a26af50e8cbf565e
ep_bytes: 558bec6aff6868cb46006874a7460064
timestamp: 2021-10-11 02:39:20

Version Info:

CompanyName: Astonsoft
FileDescription: EssentialPIM
FileVersion: 9.5.2.0
LegalCopyright: Astonsoft Ltd.
ProductName: EssentialPIM
ProductVersion: 9.5.2.0
Translation: 0x0409 0x04e4

Zusy.403365 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.403365
FireEyeGeneric.mg.8d1c723a603a0a97
ALYacGen:Variant.Zusy.403365
K7AntiVirusTrojan ( 005607891 )
K7GWTrojan ( 005607891 )
Cybereasonmalicious.e598f8
BitDefenderThetaGen:NN.ZexaF.34084.@B0@auoAJ7Ck
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HBAT
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.Win32.TeviRat.gen
BitDefenderGen:Variant.Zusy.403365
AvastWin32:MalwareX-gen [Trj]
Ad-AwareGen:Variant.Zusy.403365
EmsisoftGen:Variant.Zusy.403365 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
SophosMal/Generic-S
AviraHEUR/AGEN.1142521
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.1IAKRUN
AhnLab-V3Trojan/Win.Generic.R445351
McAfeeArtemis!8D1C723A603A
MAXmalware (ai score=85)
MalwarebytesAdware.Agent.SFP.Generic
APEXMalicious
RisingTrojan.Kryptik!1.AA55 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HLMN!tr
AVGWin32:MalwareX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Zusy.403365?

Zusy.403365 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment