Malware

Should I remove “Zusy.404828”?

Malware Removal

The Zusy.404828 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.404828 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Zusy.404828?


File Info:

name: 0DD0094FD898E462FF16.mlw
path: /opt/CAPEv2/storage/binaries/f69e0fe6f2b064d87c28f5d84c5085d7206f388315c2a61f55bb15c65ca513ab
crc32: 349E74EA
md5: 0dd0094fd898e462ff16af9dfc4bf441
sha1: b512be03d3965b6ca9bb361646cd35e6564c106c
sha256: f69e0fe6f2b064d87c28f5d84c5085d7206f388315c2a61f55bb15c65ca513ab
sha512: e744e79e1261ca374a0510247e8bdc2d8988a0fd7b7277cc776ee17f830c7a870c49668c602cc2f9ed4d30cf410e163d13cfcbff467a77ee1ba15dd8936c2fb3
ssdeep: 24576:+292Tr2ee32T2928b2GFJ2m4poXN2j28mhkIv2HpxgPh01z:+292Tr2ee32T292y2GP2LkNu9mh01
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T145357B35730CA379C5574676CE168EEA7E224ED0B710E597B3A83E0E36B2984742D783
sha3_384: d957180d6eb7cf76a708f5f828bc9e893c0c09bd689ed7c2fbdcb70fb8f20188e8b9ffdbc36ca9f6dc72ff973dcd9fd5
ep_bytes: 558bec6aff68d0c74600686ca1460064
timestamp: 2021-10-22 13:29:18

Version Info:

CompanyName: Cat Logic
FileDescription: Домашняя библиотека
InternalName: Catalogic Book List
LegalCopyright: Cat Logic
ProductName: CatList
ProductVersion:
Comments:
FileVersion: 0.8.0.13
LegalTrademarks:
OriginalFilename:
Translation: 0x0419 0x04e3

Zusy.404828 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGen:Variant.Zusy.404828
CAT-QuickHealTrojan.GenericPMF.S24130058
McAfeeGenericRXAA-AA!0DD0094FD898
K7AntiVirusTrojan ( 005821bc1 )
K7GWTrojan ( 005821bc1 )
CyrenW32/Kryptik.FPV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLIQ
APEXMalicious
KasperskyHEUR:Trojan.Win32.Staser.gen
BitDefenderGen:Variant.Zusy.404828
MicroWorld-eScanGen:Variant.Zusy.404828
AvastWin32:CrypterX-gen [Trj]
EmsisoftGen:Variant.Zusy.404828 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1135762
MAXmalware (ai score=85)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.Win32.Staser.gen
GDataWin32.Trojan.PSE.13M60MZ
AhnLab-V3Trojan/Win.UA.C4723580
BitDefenderThetaGen:NN.ZexaF.34182.gz0@a8nQG@ai
ALYacGen:Variant.Zusy.404828
MalwarebytesAdware.Agent.SFP.Generic
RisingBackdoor.TeviRat!8.1089E (TFE:dGZlOgEUPJb2/ToZ4Q)
FortinetW32/Kryptik.HATU!tr
AVGWin32:CrypterX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Zusy.404828?

Zusy.404828 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment