Malware

Zusy.408243 (B) malicious file

Malware Removal

The Zusy.408243 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.408243 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Latvian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Anomalous binary characteristics

How to determine Zusy.408243 (B)?


File Info:

name: 52283569730F9C34D577.mlw
path: /opt/CAPEv2/storage/binaries/f106de8a542e0a2f93bbc41a06d6ce68d0b57eb82ad90925de58eff189835568
crc32: 1E5F7219
md5: 52283569730f9c34d577c92eb5f4ccdd
sha1: e82fd0fcae8d9080302be4eace168d729fdfe2aa
sha256: f106de8a542e0a2f93bbc41a06d6ce68d0b57eb82ad90925de58eff189835568
sha512: 4491c260f269ca09d650d6ea4f71b62a8088242b0c289263bab247fcd57bf048bc1920cc4e49974ef29f70e145ab933796a8f8cbbcecfad2de06b1acaa8b1f28
ssdeep: 6144:QJkVpPsVYLBT3177BGZvSqiZY2SN9J20g1XI8wZf:QKrPsuLBT3lIl6vSHJ231XIt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13F44E02177B19C72E9B71A3028B0D3712A77B4326A75828B3768473D5F607D29FA4363
sha3_384: 17208d8d5296c0d1abb00ae082edec74517e02c3a0cf41120f0c7274225f86b755d4183a25f11dd0b70c973dd0383e48
ep_bytes: e88f2c0000e989feffffcccccccccccc
timestamp: 2020-07-31 23:32:54

Version Info:

InternalName: bomgpiaruci.iwa
Copyright: Copyrighz (C) 2021, fudkat
ProductVersion: 13.54.77.25
Translation: 0x0114 0x046a

Zusy.408243 (B) also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.408243
ALYacGen:Variant.Zusy.408243
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00589d2d1 )
K7GWTrojan ( 00589d2d1 )
Cybereasonmalicious.cae8d9
CyrenW32/StopCrypt.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNKW
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Stealer.akhm
BitDefenderGen:Variant.Zusy.408243
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Zusy.408243
SophosMal/Agent-AWV
McAfee-GW-EditionLockbit-FSWW!52283569730F
FireEyeGeneric.mg.52283569730f9c34
EmsisoftGen:Variant.Zusy.408243 (B)
IkarusTrojan-Ransom.StopCrypt
GDataGen:Variant.Zusy.408243
AviraTR/AD.GenSHCode.wdbna
eGambitPE.Heur.InvalidSig
MicrosoftTrojan:Win32/Azorult.RT!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.MalPE.R452832
Acronissuspicious
McAfeeLockbit-FSWW!52283569730F
MAXmalware (ai score=86)
MalwarebytesTrojan.MalPack.GS
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Lockbit.FSWW!tr
BitDefenderThetaGen:NN.ZexaF.34294.qq1@aqVMfQiI
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Zusy.408243 (B)?

Zusy.408243 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment