Malware

Zusy.404814 malicious file

Malware Removal

The Zusy.404814 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.404814 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Terminates another process
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Zusy.404814?


File Info:

name: A03DF291FAE9AFC74ED8.mlw
path: /opt/CAPEv2/storage/binaries/5da02136cc8dcef098500eb9d07aa6a1700744541ea88173019ca08e5a3a53f3
crc32: 549D1664
md5: a03df291fae9afc74ed8b15cf9b2c4a0
sha1: 2cc4d1f680b5620136490495155c4d1f64a12061
sha256: 5da02136cc8dcef098500eb9d07aa6a1700744541ea88173019ca08e5a3a53f3
sha512: abafc49f916af2189a12636f8f21288e3f8a3089fbacf1b5fe120d9513c7cff5a295153df6bf938949a4e96a01cbc6665886d51713782f76c2fef87c9365802c
ssdeep: 24576:DOIDzubP0pt5cIfUog6jN2j28mhkIv2HpxgPh01e:DOIDzurKHcIfUog6jNuRmh01
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DE358C35730CA37AC55746B6CE568EEA7E314ED0B710E997B2683D0E36B2984702D783
sha3_384: 92d2c2b18f6e48193d615aa6adf5ed6591188a32c50489b47cc43e575f3c6956314f3dc3a5a9ba3a239ad6221134b9b3
ep_bytes: 558bec6aff6828c8460068f4a1460064
timestamp: 2021-10-20 18:39:08

Version Info:

CompanyName: Cat Logic
FileDescription: Домашняя библиотека
InternalName: Catalogic Book List
LegalCopyright: Cat Logic
ProductName: CatList
ProductVersion:
Comments:
FileVersion: 0.8.0.13
LegalTrademarks:
OriginalFilename:
Translation: 0x0419 0x04e3

Zusy.404814 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.404814
CAT-QuickHealTrojan.GenericPMF.S24130058
ALYacGen:Variant.Zusy.404814
K7AntiVirusTrojan ( 005821bc1 )
K7GWTrojan ( 005821bc1 )
ArcabitTrojan.Zusy.D62D4E
CyrenW32/Bulz.BP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HBFP
APEXMalicious
KasperskyHEUR:Trojan.Win32.Staser.gen
BitDefenderGen:Variant.Zusy.404814
AvastWin32:Trojan-gen
TencentTrojan.Win32.Staser.wc
Ad-AwareGen:Variant.Zusy.404814
EmsisoftGen:Variant.Zusy.404814 (B)
VIPREGen:Variant.Zusy.404814
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.a03df291fae9afc7
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1244224
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.Win32.Staser.gen
GDataWin32.Trojan.PSE.15D813Y
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.UA.R446703
Acronissuspicious
McAfeeGenericRXAA-AA!A03DF291FAE9
MAXmalware (ai score=80)
MalwarebytesAdware.Agent.SFP.Generic
RisingTrojan.Kryptik!1.AA55 (CLASSIC)
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HATU!tr
BitDefenderThetaGen:NN.ZexaE.34806.gz0@a4p4yzbi
AVGWin32:Trojan-gen

How to remove Zusy.404814?

Zusy.404814 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment