Malware

What is “Zusy.409378”?

Malware Removal

The Zusy.409378 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.409378 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Zusy.409378?


File Info:

name: 7679E288A4178366D40C.mlw
path: /opt/CAPEv2/storage/binaries/761f8a03994e6ed69ddca7ab9205fa7895206c874a63d27b48785741e1f4be11
crc32: B966E1B6
md5: 7679e288a4178366d40ccc99fc28d1fd
sha1: 09d1b4988ad09def9c347728e63d8322ce9a485b
sha256: 761f8a03994e6ed69ddca7ab9205fa7895206c874a63d27b48785741e1f4be11
sha512: d0638569024781e339a24b87429a5f1f6a1717d4333910e84c7d8a6a3b5f4f249db10e75aa4efc566b4869b3750fb96af6f7990a242597c0db198cefab26e004
ssdeep: 24576:evBNs70PdiZ/zmkZN2j28mhkI72HpxgPh01R:en+0PgZbmkNudmh01
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T174358C35730CA339C5574676CE168EEA7E224ED0B710E997B3683E0E36B2984746D783
sha3_384: 36c4b6b10ba7dff81fd2310e9f863c604cce042b1ed9f2522019cc242af591919fd7a3c7f4c28965d0c3a43ad7fc881d
ep_bytes: 558bec6aff6800c8460068b8a1460064
timestamp: 2021-10-21 20:31:42

Version Info:

CompanyName: Cat Logic
FileDescription: Домашняя библиотека
InternalName: Catalogic Book List
LegalCopyright: Cat Logic
ProductName: CatList
ProductVersion:
Comments:
FileVersion: 0.8.0.13
LegalTrademarks:
OriginalFilename:
Translation: 0x0419 0x04e3

Zusy.409378 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.409378
FireEyeGen:Variant.Zusy.409378
CAT-QuickHealTrojan.GenericPMF.S24130058
McAfeeGenericRXAA-AA!7679E288A417
K7AntiVirusTrojan ( 005821bc1 )
K7GWTrojan ( 005821bc1 )
CrowdStrikewin/malicious_confidence_60% (W)
CyrenW32/Bulz.BP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLIQ
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Staser.gen
BitDefenderGen:Variant.Zusy.409378
SUPERAntiSpywareTrojan.Agent/Gen-Fragtor
Ad-AwareGen:Variant.Zusy.409378
McAfee-GW-EditionBehavesLike.Win32.BadFile.tc
EmsisoftGen:Variant.Zusy.409378 (B)
AviraHEUR/AGEN.1120914
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.13M60MZ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.UA.R446703
ALYacGen:Variant.Zusy.409378
MAXmalware (ai score=84)
MalwarebytesAdware.Agent.SFP.Generic
RisingTrojan.Kryptik!1.AA55 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HATU!tr
BitDefenderThetaGen:NN.ZexaE.34084.gz0@aqX5kgji
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen

How to remove Zusy.409378?

Zusy.409378 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment