Malware

About “Zusy.406813” infection

Malware Removal

The Zusy.406813 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.406813 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine Zusy.406813?


File Info:

name: 8EB056ABC6001118DBE5.mlw
path: /opt/CAPEv2/storage/binaries/0119a2167f5774efdbaef5af5f9aba7ac13f3391d9bdad781620c22a3d80e081
crc32: 082BD9ED
md5: 8eb056abc6001118dbe56768c6f4dec5
sha1: bd9d4c277a7c46c724fbb0b090bbb22020a77f54
sha256: 0119a2167f5774efdbaef5af5f9aba7ac13f3391d9bdad781620c22a3d80e081
sha512: c8bff3410dbdfcff4cac82de206abce6045905051eecf54490318aca7c499379703d01b9a61a12640c63fca632dead8cbae977785b49f64e88512f3a7ba0c21a
ssdeep: 12288:xzti60jvE6kNdwlEIfqPtsh1jUt/ed3LG/0TjDiD4:xzt/0jvE6NSqqFshBUM16/1D4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T125E47B32B7C2C07AD57311735914B2A990AFBF314839954BBBC82B1E2E745C1EE29B17
sha3_384: 8c7a2aad6f5c5f2e5ffbdceb25172453b7933889a10aafb69cb75dd19f6b52dc73ce6433fad23d38cfc1ac09cbe96c6d
ep_bytes: e856270100e97ffeffff558bec83ec20
timestamp: 2019-11-09 05:32:11

Version Info:

0: [No Data]

Zusy.406813 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.406813
FireEyeGeneric.mg.8eb056abc6001118
McAfeePUP-XBV-NT
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AlibabaAdWare:Win32/Neoreklami.5e89b7bc
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaAI:Packer.68F7B8E61F
CyrenW32/Neoreklami.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.Neoreklami.GX
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.Win32.Neoreklami.gen
BitDefenderGen:Variant.Zusy.406813
NANO-AntivirusRiskware.Win32.Neoreklami.isheyf
AvastWin32:Adware-gen [Adw]
Ad-AwareGen:Variant.Zusy.406813
EmsisoftGen:Variant.Zusy.406813 (B)
ComodoMalware@#3n1kf81fyvd5i
ZillyaAdware.Neoreklami.Win32.15117
McAfee-GW-EditionBehavesLike.Win32.PUPXBV.jh
SophosMal/Generic-R + Troj/Agent-BGBV
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.406813
AviraHEUR/AGEN.1106534
Antiy-AVLTrojan/Generic.ASMalwS.308872C
ArcabitTrojan.Zusy.D6351D
MicrosoftTrojan:Win32/Occamy.C01
CynetMalicious (score: 99)
AhnLab-V3PUP/Win.Neoreklami.R417232
VBA32BScope.Trojan.BPlug
ALYacGen:Variant.Zusy.406813
MAXmalware (ai score=85)
MalwarebytesAdware.Neoreklami
RisingTrojan.Generic@ML.100 (RDML:gVU3Sbm96QqJqhXl3ZV5ng)
IkarusPUA.Neoreklami
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Generic_PUA_LN
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.bc6001
PandaTrj/Genetic.gen

How to remove Zusy.406813?

Zusy.406813 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment