Malware

Zusy.407839 (B) malicious file

Malware Removal

The Zusy.407839 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.407839 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Authenticode signature is invalid
  • CAPE detected the Vidar malware family
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Zusy.407839 (B)?


File Info:

name: CBAC36B4DE65EB6FA0D6.mlw
path: /opt/CAPEv2/storage/binaries/f8c2ea4c4c48c6a4240fda2018e39114df48e7f0c4906da128c5d18a3f90aa24
crc32: AD18FEAB
md5: cbac36b4de65eb6fa0d6586d13eddcb9
sha1: b4dff0a28c3bfad179ec6713ef641c543058e533
sha256: f8c2ea4c4c48c6a4240fda2018e39114df48e7f0c4906da128c5d18a3f90aa24
sha512: c6f48cfe47b90b2bc659ab21e2395cd41f4f665d7816c756fe34a19916925a3f42a01c94b425d95b505555904c7eea4425dcb9f93b1243848fb4a746538d1e40
ssdeep: 24576:9vxTKDKumJcHgHvYE5z6+KT81Z3xZHysccSUo:3TOm4E5z+gHHtcxU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FD05AE91F6C3E0B1D90222B65A63573F193076075332CDC7EBD02E1A9A611E1AABF35D
sha3_384: 81a7c38c638727102957bd8b25b6ad3185bc5790e99f2ab73d82372e4fb370b10624622c14360edcf3f9917a06918f6c
ep_bytes: e81dac0000e989feffff8bff558bec8b
timestamp: 2021-12-27 11:32:32

Version Info:

0: [No Data]

Zusy.407839 (B) also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Chapak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.407839
FireEyeGeneric.mg.cbac36b4de65eb6f
ALYacGen:Variant.Zusy.407839
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2615623
SangforTrojan.Win32.Chapak.gen
CrowdStrikewin/malicious_confidence_100% (W)
K7GWPassword-Stealer ( 0054d1a31 )
K7AntiVirusPassword-Stealer ( 0054d1a31 )
BitDefenderThetaGen:NN.ZexaF.34114.1mW@aGH@cdl
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.Agent.OGR
TrendMicro-HouseCallTROJ_GEN.R002C0GLU21
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Chapak.gen
BitDefenderGen:Variant.Zusy.407839
AvastWin32:PWSX-gen [Trj]
TencentMalware.Win32.Gencirc.11e09791
Ad-AwareGen:Variant.Zusy.407839
EmsisoftGen:Variant.Zusy.407839 (B)
DrWebTrojan.PWS.Vidar.16
VIPRETrojan-Spy.Win32.Zbot.gen (v)
TrendMicroTROJ_GEN.R002C0GLU21
McAfee-GW-EditionBehavesLike.Win32.Pykse.ch
SophosMal/Generic-S
IkarusTrojan-PSW.Agent
GDataGen:Variant.Zusy.407839
AviraHEUR/AGEN.1143724
MAXmalware (ai score=80)
APEXMalicious
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.SpyAgent.C4692354
McAfeeGenericRXRG-SS!CBAC36B4DE65
VBA32BScope.Trojan.Chapak
MalwarebytesMalware.AI.3169659849
RisingStealer.OskiStealer!1.C41E (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Emotet.BN!tr
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.28c3bf
PandaTrj/GdSda.A

How to remove Zusy.407839 (B)?

Zusy.407839 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment