Malware

Zusy.406281 removal instruction

Malware Removal

The Zusy.406281 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.406281 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Latvian
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Zusy.406281?


File Info:

crc32: 88A61936
md5: 51b81c5676aa5f4ffa12fb658393d164
name: 51B81C5676AA5F4FFA12FB658393D164.mlw
sha1: 594af5a70eff70dad4c50db126b4c73976a41758
sha256: 4c6609decd817271657f1f8dd867d8e01137c65c0781f55c0f18048fe9291ae9
sha512: 08250e054bdfe7aba1d1d2210e31a9ae5f2f92d633fcef2950d179d9a9de2bef768c2627c3c7343e8ce19f84705025697fe9b1b722d7ba394b4a60f851e395c7
ssdeep: 49152:G4y555555555555555555555555555555555555555555555555555555555555:G4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: bomgpiaruci.iwa
ProductVersion: 15.54.12.31
Copyright: Copyrighz (C) 2021, fudkagat
Translation: 0x0114 0x046a

Zusy.406281 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0058a0981 )
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.36052
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.406281
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaBackdoor:Win32/Krypter.6d2f4a7e
K7GWTrojan ( 0058a0981 )
Cybereasonmalicious.70eff7
CyrenW32/Kryptik.FOQ.gen!Eldorado
SymantecPacked.Generic.528
ESET-NOD32a variant of Win32/Kryptik.HNFM
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Trojan.Generic-9906289-0
KasperskyHEUR:Backdoor.Win32.Tofsee.gen
BitDefenderGen:Variant.Zusy.406281
MicroWorld-eScanGen:Variant.Zusy.406281
TencentMalware.Win32.Gencirc.11d6cf34
Ad-AwareGen:Variant.Zusy.406281
BitDefenderThetaGen:NN.ZexaF.34266.@t0@aOb8OroI
TrendMicroMal_Tofsee
McAfee-GW-EditionBehavesLike.Win32.Worm.vh
FireEyeGeneric.mg.51b81c5676aa5f4f
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
Antiy-AVLTrojan/Generic.ASMalwS.34CB788
MicrosoftRansom:Win32/StopCrypt.PS!MTB
ArcabitTrojan.Zusy.D63309
GDataGen:Variant.Zusy.406281
AhnLab-V3Trojan/Win.OC.R449038
Acronissuspicious
McAfeePacked-GDV!51B81C5676AA
MAXmalware (ai score=86)
VBA32Malware-Cryptor.2LA.gen
MalwarebytesTrojan.MalPack
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_Tofsee
RisingTrojan.Generic@ML.99 (RDMK:mhgvKdj3ZFlgZ2zckh82Qw)
IkarusTrojan-Ransom.StopCrypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.FQN!tr
AVGWin32:MalwareX-gen [Trj]

How to remove Zusy.406281?

Zusy.406281 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment