Malware

About “Zusy.409895” infection

Malware Removal

The Zusy.409895 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.409895 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing
  • Created a process from a suspicious location
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • Created a service that was not started

How to determine Zusy.409895?


File Info:

name: 65A6BF4F580343B522C7.mlw
path: /opt/CAPEv2/storage/binaries/65c933eeeb89a2456a72f6e1144ee042ea4e96eafc7ec23feec921706126903b
crc32: 5B0F1B73
md5: 65a6bf4f580343b522c7fca1c7017d97
sha1: d6ad8504ee71d0eac41ea2c3bbc48e0e2eeeaf34
sha256: 65c933eeeb89a2456a72f6e1144ee042ea4e96eafc7ec23feec921706126903b
sha512: 180eeb2e3b892fca91c10d4a4da5b2b7d256f607ce006f09722113bdf05f2d7c3a0c9289ac138277810ca3754a26b890e0c54b6568a0a9e30807b032044a567b
ssdeep: 49152:yJ1q6bpYBqYuE3OGKfiklP5AiICiITAxblm:IpYBb57iP5AigIOl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1389501396372C03AC4501678CC699BF6167C7F70FA29C54377B87E867B726C2B622285
sha3_384: 043d8cc264ce08db9c769ea48abfd1c06dcec924ea5953c0981ef083f72da7ab9a66a2d4f03fba4fa4b8ba13d1c4f8df
ep_bytes: 558bec6aff68d8ab5700681487570064
timestamp: 2021-12-02 11:15:21

Version Info:

0: [No Data]

Zusy.409895 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.409895
FireEyeGeneric.mg.65a6bf4f580343b5
McAfeeGenericRXRA-PA!65A6BF4F5803
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005606b51 )
AlibabaTrojan:Win32/Injuke.8b1d05a9
K7GWTrojan ( 005606b51 )
CyrenW32/FakeAlert.FY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HBAI
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Injuke.gen
BitDefenderGen:Variant.Zusy.409895
AvastWin32:CrypterX-gen [Trj]
TencentWin32.Trojan.Injuke.Wpjq
Ad-AwareGen:Variant.Zusy.409895
EmsisoftGen:Variant.Zusy.409895 (B)
DrWebTrojan.Siggen16.1876
TrendMicroTROJ_GEN.R002C0WL921
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1QRPSAL
AviraHEUR/AGEN.1142521
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Trojan/Win.Generic.R455965
BitDefenderThetaGen:NN.ZexaE.34084.9DW@aKov4Xsi
ALYacGen:Variant.Zusy.409895
MAXmalware (ai score=86)
VBA32Trojan.Injuke
TrendMicro-HouseCallTROJ_GEN.R002C0WL921
RisingTrojan.Kryptik!1.AA55 (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HATU!tr
AVGWin32:CrypterX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Zusy.409895?

Zusy.409895 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment