Malware

Zusy.405349 (file analysis)

Malware Removal

The Zusy.405349 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.405349 virus can do?

  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Zusy.405349?


File Info:

crc32: A5DE4C3B
md5: 59e1ba04021f1309e1768d49095bf99c
name: 59E1BA04021F1309E1768D49095BF99C.mlw
sha1: abb15bf05cd9168e8e780a48e894139114d3c1d3
sha256: 2137cab42fa1f52fa897594e5e32e9c0769319da63a8a38eeee09f0cdd5a89cb
sha512: eda8a7505baee1d135a35ccaddd932a3c33a6bbc50ad0baddfbb16729f8dcfbf9a9cea6ca76c25bc3c796cc0b77453e85df4dfc3ed4288ae35cdf11c2255219b
ssdeep: 49152:sOUN9EcFMHzBfw2t145u6pGs3SQyRTGb+BkgCt7Y5:sOUN9M9bcuqS55BPV
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.405349 also known as:

K7AntiVirusTrojan ( 0053ea151 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.405349
CylanceUnsafe
AlibabaTrojan:Win32/GenKryptik.c89c761e
K7GWTrojan ( 0053ea151 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.CVON
APEXMalicious
AvastWin32:StartSurf-B [Adw]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.405349
NANO-AntivirusTrojan.Win32.Chapak.fkgiri
MicroWorld-eScanGen:Variant.Zusy.405349
TencentWin32.Trojan.Generic.Szlp
Ad-AwareGen:Variant.Zusy.405349
SophosGeneric PUA KL (PUA)
BitDefenderThetaGen:NN.ZexaF.34294.awW@aaQlMVhk
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.59e1ba04021f1309
EmsisoftGen:Variant.Zusy.405349 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.StartSurf.qqk
AviraHEUR/AGEN.1103297
Antiy-AVLTrojan/Generic.ASMalwS.28CBA5B
MicrosoftTrojan:Win32/Tnega!ml
GDataGen:Variant.Zusy.405349
AhnLab-V3PUP/Win32.Agent.R242331
Acronissuspicious
McAfeeArtemis!59E1BA04021F
VBA32BScope.Trojan.Wacatac
MalwarebytesAdware.IStartSurf
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B477 (CLASSIC)
YandexTrojan.GenAsa!5o0RpjaA/qI
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.COAQ!tr
AVGWin32:StartSurf-B [Adw]

How to remove Zusy.405349?

Zusy.405349 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment