Malware

Zusy.409790 (file analysis)

Malware Removal

The Zusy.409790 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.409790 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Creates a copy of itself

How to determine Zusy.409790?


File Info:

name: 2358EDAC359B6D31BECB.mlw
path: /opt/CAPEv2/storage/binaries/f497702c557f1437a877224360f195d4957ac2d69134dcbec8e88f869150f49d
crc32: 282877E6
md5: 2358edac359b6d31becb3f4000f37388
sha1: 1df2b337d330ba4c4d33c0b1b3e55abee9e56e5d
sha256: f497702c557f1437a877224360f195d4957ac2d69134dcbec8e88f869150f49d
sha512: d71a28417fbd8541c82e7b3797904f7110a49c7b35f2fb9ca13e99c1227d68a1ae61c7b71884f777be8ff88b362a5090d80598755104671a0168a2df5c2a60fb
ssdeep: 24576:PmaHepn3RIFeyHZnXnnCILzw47AfIAa4XiHWh1f3:eaHepn3RIFe2ZnXnnCILzh7AAAa2iif
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B1D5A7A162A4E9A2F20636B4C5F3A6B03D7D7C18E3701D87705E7D99F27818634393A7
sha3_384: b037dd90b50a01420b46e4c842a557706144e62492d54aa60e9bc3e2fc0a1e603b7179eb8d579c183cd51a56571279bc
ep_bytes: 558bec6aff68c8c946006884a4460064
timestamp: 2021-08-15 09:56:51

Version Info:

CompanyName: MiniTool
FileDescription: MiniTool ShadowMaker
FileVersion: 0.9.0.23
InternalName: system_b.exe
LegalCopyright: Copyright (C) 2016
OriginalFilename: system_b.exe
ProductName: MiniTool ShadowMaker
ProductVersion: 0.9.0.23
Translation: 0x0409 0x04b0

Zusy.409790 also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.409790
FireEyeGeneric.mg.2358edac359b6d31
CAT-QuickHealTrojan.GenericIH.S22364309
ALYacGen:Variant.Zusy.409790
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
K7AntiVirusTrojan ( 005690671 )
K7GWTrojan ( 005690671 )
Cybereasonmalicious.7d330b
BitDefenderThetaGen:NN.ZexaF.34742.WA0@aa2p0vdk
CyrenW32/Kryptik.FAD.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HLIQ
APEXMalicious
KasperskyHEUR:Trojan.Win32.Staser.gen
BitDefenderGen:Variant.Zusy.409790
AvastFileRepMalware
TencentTrojan.Win32.Staser.wc
Ad-AwareGen:Variant.Zusy.409790
SophosMal/Generic-S
McAfee-GW-EditionGenericRXPT-PN!2358EDAC359B
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zusy.409790 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.18W14TU
AviraHEUR/AGEN.1244176
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R421535
Acronissuspicious
McAfeeGenericRXPT-PN!2358EDAC359B
MalwarebytesAdware.DownloadAssistant
RisingTrojan.Kryptik!1.AA55 (CLASSIC)
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HATU!tr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Zusy.409790?

Zusy.409790 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment