Malware

Should I remove “Zusy.405314”?

Malware Removal

The Zusy.405314 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.405314 virus can do?

  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

How to determine Zusy.405314?


File Info:

name: 7D5B8539A78B5FB27249.mlw
path: /opt/CAPEv2/storage/binaries/3758eba9c8bc4d186bf7ab04751fa30f55c616e2bddc26a395011b8a9766fd90
crc32: 84406618
md5: 7d5b8539a78b5fb272495f1441df9d7c
sha1: 2ba75e63907a45cf2ed2c1d6e8dd668f43c9bafe
sha256: 3758eba9c8bc4d186bf7ab04751fa30f55c616e2bddc26a395011b8a9766fd90
sha512: dc4addd29b6683cadaf0e101c788173593cd247f9472047d904ed3160b11190b47e2449b6e5dc734219184dd16aad92598979089da1c47576a75c39bc47a501a
ssdeep: 98304:tEmxo9zUJKzZsCRijksmEFgWVBqvq3BIkwWUTV:i6o9zUJK1sCYYcKD8IknUTV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14BF51277F084EEC8FE8AC5F5C6A7D549478846704CED2449246A88C1CFF0267B76FA68
sha3_384: 056a5acbcb4b1ca9b309e28017c644c3f6dda2462928c32785364aa6ad0644ad89375bb6029c1528d3b6ad929d8738e7
ep_bytes: 558d6c249881ec0c02000056e9080e00
timestamp: 2021-11-22 17:13:18

Version Info:

0: [No Data]

Zusy.405314 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.405314
FireEyeGeneric.mg.7d5b8539a78b5fb2
CAT-QuickHealTrojan.Wacatac.S15862760
McAfeeGenericRXIP-YP!7D5B8539A78B
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan ( 0056cc351 )
K7AntiVirusTrojan ( 0056cc351 )
CyrenW32/S-0cb2f1a4!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GOGM
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.405314
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Variant.Zusy.405314
SophosML/PE-A + Troj/AGent-BFHO
DrWebTrojan.PackedENT.124
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
EmsisoftGen:Variant.Zusy.405314 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Crypt.XPACK.Gen3
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASBOL.C639
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Zusy.405314
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R346633
VBA32BScope.Trojan.PackedENT
MalwarebytesTrojan.Crypt.Generic
RisingTrojan.Kryptik!1.BBF5 (CLASSIC)
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_98%
FortinetW32/Kryptik.GOGM!tr
BitDefenderThetaAI:Packer.BE3F95411E
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.9a78b5

How to remove Zusy.405314?

Zusy.405314 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment