Malware

Should I remove “Zusy.405907 (B)”?

Malware Removal

The Zusy.405907 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.405907 (B) virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid

How to determine Zusy.405907 (B)?


File Info:

name: BB84E5D55C539A937EAD.mlw
path: /opt/CAPEv2/storage/binaries/76f017d98ac564fc781b1b04b257b1ef0439c3b91ae2ee61c6053d94836c55f5
crc32: DB25394D
md5: bb84e5d55c539a937ead33a1e383e733
sha1: 2317992e9ef25dfe3cc650b92c581523988d0d5c
sha256: 76f017d98ac564fc781b1b04b257b1ef0439c3b91ae2ee61c6053d94836c55f5
sha512: 428ae7800521b4d91f9d0f8d09f2619761425bbf2344d4870f5c0eb7c756032152be9a0fe589b31c606fc366f3dd4132c322169a61e998fa64111ff90c8ebefc
ssdeep: 98304:3QKf3aCohSMx4DY3VNNXauOq5aMuPARqM8vTSWkzEW3nwunLvGHasJL:3V3USMx4kHAuOwhuLM87xq3w5asx
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T18846237323360089E0E4CD39C237BEA932F707665B42AC7D96DB19D227125B9F352A53
sha3_384: 797a9cf7b97e1a63ca80658167b73894f1c574bdf2961056eabfe702040ebeda7969b4bf54c2fdd5c01bc786e048bc1b
ep_bytes: 681c6a6dfee823f0fcff57c3ff742500
timestamp: 2021-11-01 06:38:37

Version Info:

0: [No Data]

Zusy.405907 (B) also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Agent.a!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.405907
FireEyeGeneric.mg.bb84e5d55c539a93
McAfeeArtemis!BB84E5D55C53
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 7000001c1 )
AlibabaPacked:Win32/VMProtect.59b71ff3
K7GWTrojan ( 7000001c1 )
Cybereasonmalicious.55c539
BitDefenderThetaGen:NN.ZexaF.34232.@FW@aSjYeUmi
CyrenW32/Zusy.HP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.VMProtect.AR suspicious
TrendMicro-HouseCallTROJ_GEN.R002C0RK921
Paloaltogeneric.ml
ClamAVWin.Malware.Vmprotbad-9855134-0
KasperskyTrojan-Downloader.Win32.Agent.xxzuif
BitDefenderGen:Variant.Zusy.405907
AvastWin32:Malware-gen
TencentWin32.Trojan-downloader.Agent.Phqa
Ad-AwareGen:Variant.Zusy.405907
EmsisoftGen:Variant.Zusy.405907 (B)
F-SecureTrojan.TR/AD.ChiDldr.yvywt
ZillyaAdware.VMProtect.Win32.57
TrendMicroTROJ_GEN.R002C0RK921
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosMal/Generic-R + Mal/VMProtBad-A
IkarusPUA.GameHack
GDataGen:Variant.Zusy.405907
JiangminTrojanDownloader.Agent.gbfn
AviraTR/AD.ChiDldr.yvywt
MAXmalware (ai score=85)
Antiy-AVLTrojan[Downloader]/Win32.Agent
GridinsoftTrojan.Win32.Agent.oa!s5
ArcabitTrojan.Zusy.D63193
ZoneAlarmTrojan-Downloader.Win32.Agent.xxzuif
MicrosoftTrojan:Win32/Tnega!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Reputation.C4398773
VBA32TScope.Malware-Cryptor.SB
ALYacGen:Variant.Zusy.405907
MalwarebytesMalware.Heuristic.1003
APEXMalicious
RisingTrojan.Generic@AI.95 (RDMK:NWrh3yMKtJE2BMA/FS2oaA)
YandexRiskware.VMProtect!/XvsKhBP9L8
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetW32/Agent.ADER!tr
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.879860.susgen

How to remove Zusy.405907 (B)?

Zusy.405907 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment