Malware

How to remove “Zusy.407739 (B)”?

Malware Removal

The Zusy.407739 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.407739 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Zusy.407739 (B)?


File Info:

name: 6D5E597585E9DBE81C8E.mlw
path: /opt/CAPEv2/storage/binaries/2d204cebfd7b8843534d12542af6d54ac23f1f594398a99d32a6f64cb561dfa6
crc32: 6F0F050D
md5: 6d5e597585e9dbe81c8e5f4db6f1eb4c
sha1: bb63d1f52ff6fec3ca21110433c1b699fb0e98ac
sha256: 2d204cebfd7b8843534d12542af6d54ac23f1f594398a99d32a6f64cb561dfa6
sha512: 466ba64690e9557a3fa8a574f1dd0096b7096087e392f0523690e11bccc73b921072d8242ee154d9a291a472f26aea7843ef226e24164f538b4350f1e53ddc89
ssdeep: 98304:WZs7LVfZcrrBZs7LVfZcrrBZs7LVfZcrrBZs7LVfZcrrBZs7LVfZcrrBZs7LVfZY:5fwP0fwP0fwP0fwP0fwP0fwP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T171769F3AF690C537C1236E38DC5BE2689C25BEE11D1424877BE93E8D9F397823426197
sha3_384: dbcf3008ea2e7368f9232860afc89001e724744013b35c436d56d900679c4b6f95f393bc8f2cfdc16a3184cb3d1a8f48
ep_bytes: 558becb9280000006a006a004975f953
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Zusy.407739 (B) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.407739
FireEyeGeneric.mg.6d5e597585e9dbe8
CAT-QuickHealTrojan.Dynamer.A4
ALYacGen:Variant.Zusy.407739
CylanceUnsafe
K7AntiVirusTrojan ( 005896cb1 )
BitDefenderGen:Variant.Zusy.407739
K7GWTrojan ( 003cee3e1 )
Cybereasonmalicious.585e9d
CyrenW32/Agent.AKD.gen!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/Injector.TXR
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Agent.spvx
NANO-AntivirusTrojan.Win32.Agent.cscaqs
ViRobotTrojan.Win32.A.Agent.1259520
RisingTrojan.Injector!1.DA79 (RDMK:cmRtazp5atzOYuDo5ZGmBXvSs/ez)
EmsisoftGen:Variant.Zusy.407739 (B)
DrWebTrojan.Inject1.5890
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Agent.gbto
AviraTR/Inject.sbbeiuu
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASBOL.C6B2
MicrosoftTrojan:Win32/Sabsik!ml
ZoneAlarmTrojan.Win32.Agent.spvx
GDataGen:Variant.Zusy.407739
AhnLab-V3Trojan/Win32.Agent.R174319
McAfeeGenericR-FYS!6D5E597585E9
TACHYONTrojan/W32.DP-Agent.7188480
VBA32Trojan.Agent
MalwarebytesTrojan.Injector
TencentTrojan.Win32.Agent.ha
YandexTrojan.Agent!uSNBgJqCUPw
FortinetW32/Dropper.XUQ!tr
BitDefenderThetaAI:Packer.FACBA3B421
AVGWin32:MBRlock-DV [Trj]
AvastWin32:MBRlock-DV [Trj]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Zusy.407739 (B)?

Zusy.407739 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment