Malware

Zusy.406037 information

Malware Removal

The Zusy.406037 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.406037 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Spanish (Paraguay)
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings

Related domains:

iplogger.org
warmbeddy.top

How to determine Zusy.406037?


File Info:

crc32: BF2F7A84
md5: c872fe7c2008516d49f97214fae2a549
name: C872FE7C2008516D49F97214FAE2A549.mlw
sha1: 7043ce27ea431ba8a22d8cf5f2fac524098cb57b
sha256: 0742439d984746c161b9d7ee463fc07149156480c6a14263c6f6a9e0d170bbf9
sha512: 6e2502f37548ec8d54bed0517452c35ed7c6ed9b362959b87af0f2f609d417a6e65e1d2f06b3269a855d0d0e32b24508a7e52ad0453810356268f6a1368c5c8d
ssdeep: 12288:okZ7Ir2sRk6OAKchB7ePdOCkfYW+uRwYOdWTj8205GcwMNNY:NZsr2sR9OAXPqPvjW+VYdjWkKY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translations: 0x0512 0x00ac

Zusy.406037 also known as:

Elasticmalicious (high confidence)
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderGen:Variant.Zusy.406037
BaiduWin32.Trojan.Kryptik.jm
CyrenW32/Kryptik.FRX.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
MicroWorld-eScanGen:Variant.Zusy.406037
Ad-AwareGen:Variant.Zusy.406037
SophosML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Lockbit.bc
FireEyeGeneric.mg.c872fe7c2008516d
EmsisoftGen:Variant.Zusy.406037 (B)
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_95%
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Zusy.406037
AhnLab-V3Trojan/Win.MalPe.R419177
Acronissuspicious
MAXmalware (ai score=87)
VBA32BScope.Trojan.Sabsik.FL
MalwarebytesTrojan.MalPack.GS
PandaTrj/Genetic.gen
RisingMalware.Heuristic!ET#81% (RDMK:cmRtazq83GgqKfyysK0yYRL/qibg)
IkarusTrojan.Agent
MaxSecureTrojan.Malware.300983.susgen

How to remove Zusy.406037?

Zusy.406037 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment