Malware

How to remove “Zusy.406297”?

Malware Removal

The Zusy.406297 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.406297 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity

How to determine Zusy.406297?


File Info:

name: 33CD38FB16C57DE91A41.mlw
path: /opt/CAPEv2/storage/binaries/64763c4ae0501ec742b68fd7e789ccfea22c26658f1de4114f65b4487cf676b1
crc32: E09832DF
md5: 33cd38fb16c57de91a412334accfed28
sha1: d525c482fd3d28fbc4fec9894aec14b81ce9a768
sha256: 64763c4ae0501ec742b68fd7e789ccfea22c26658f1de4114f65b4487cf676b1
sha512: ec252466cfbf9d2213914c7b783d93715fa67b17c6c0f16f0b0acb4b652a869a6fc930c72abfee327b97d33e2a99694d7fa2a2ae131992a78f1cc6f2a6858de6
ssdeep: 196608:rAihxu+nl3y0SSXDa7wOdXq+qSGk1kWNF6nnu368/adP:rAsnUmDzCUkas6nu368yB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T120A6336311721145E1E6CD3EAA337ED476FA1D6B8B02A87815B6F9C626326F0F343583
sha3_384: 5f7bf1e82398133d7fd84aeb60942d2fd04e6a3c24d1f1d2aad5fdbc36c6f8d1af067e43f25f5b3f752ce9d0409e73fb
ep_bytes: 68c82aca78e8e617f9ff88d23772c1ed
timestamp: 2022-01-24 00:42:07

Version Info:

0: [No Data]

Zusy.406297 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.406297
FireEyeGeneric.mg.33cd38fb16c57de9
McAfeeArtemis!33CD38FB16C5
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0056e6e91 )
BitDefenderGen:Variant.Zusy.406297
K7GWTrojan ( 0056e6e91 )
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderThetaGen:NN.ZexaF.34182.@BW@aWw0j5lb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.VMProtect.ACR
KasperskyTrojan-GameThief.Win32.Agent.tiui
RisingMalware.Heuristic!ET#97% (RDMK:cmRtazpv6U6/6Zkdl/RxSGPuOSgN)
EmsisoftGen:Variant.Zusy.406297 (B)
ComodoTrojWare.Win32.Agent.ISVQ@5mbonp
McAfee-GW-EditionBehavesLike.Win32.Crack.tc
SentinelOneStatic AI – Malicious PE
SophosMal/Generic-S
APEXMalicious
AviraHEUR/AGEN.1144171
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmTrojan-GameThief.Win32.Agent.tiui
GDataGen:Variant.Zusy.406297
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Malware-gen.C4938428
ALYacGen:Variant.Zusy.406297
MalwarebytesTrojan.Crypt
IkarusTrojan.Win32.Krypt
FortinetW32/GenKryptik.DLII!tr
AVGFileRepMalware
Cybereasonmalicious.2fd3d2
AvastFileRepMalware

How to remove Zusy.406297?

Zusy.406297 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment