Malware

How to remove “Zusy.412090”?

Malware Removal

The Zusy.412090 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.412090 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Zusy.412090?


File Info:

name: 9F0D87827C50975AEA16.mlw
path: /opt/CAPEv2/storage/binaries/f7b58503151f2470451e423cd05a0c23bf194f88a2f89c8f544937677d957808
crc32: E3BDB7A9
md5: 9f0d87827c50975aea166042f17e20be
sha1: 629977d0a007be829bc0978333dc2fc402d6d7c5
sha256: f7b58503151f2470451e423cd05a0c23bf194f88a2f89c8f544937677d957808
sha512: 6c9c83683d862fad5b26593c4408368cc66bc8b523ede8a78010e3f0052c848ce99af68ab3aebd2a0ee59d78d4d0a61d3594474c072ff5b4a38883b6da287432
ssdeep: 6144:VWr41a+d+wXqNNobw5Ps/At/smyQTqAOLphldlYuHAGC2qS9tXhxAyi9WfEstTCg:6ik5UICETqFphlrF5qQ1AyiDWg2lvv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E6C4B00177ADFCF2D172463157BBC3F15B3DF8110A68CAAF67840A1E4AAC1937A21B56
sha3_384: e7211f676acfd1eb4b2b40f009ca45bf82b358815e2228b9346eaf116a24b8f878ee7c52126aa98c750e4f6774437d52
ep_bytes: e846060000e97afeffff3b0d68004400
timestamp: 2022-01-13 21:08:23

Version Info:

FileDescription: M1cr0
FileVersion: 1, 2, 0, 0
InternalName: M1cr0
LegalCopyright: Copyright (C) 2009 M1cr0
OriginalFilename: M1cr0.exe
ProductName: M1cr0
ProductVersion: 1, 2, 0, 0
Translation: 0x0409 0x04b0

Zusy.412090 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.412090
FireEyeGeneric.mg.9f0d87827c50975a
McAfeeGenericRXAA-AA!9F0D87827C50
Cybereasonmalicious.0a007b
BitDefenderThetaGen:NN.ZexaF.34160.Jy0@aitjn9bi
CyrenW32/Dridex.GK.gen!Eldorado
SymantecML.Attribute.HighConfidence
KasperskyHEUR:Exploit.Win32.Shellcode.gen
BitDefenderGen:Variant.Zusy.412090
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Zusy.412090
EmsisoftGen:Variant.Strictor.267632 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
SophosGeneric ML PUA (PUA)
GDataGen:Variant.Zusy.412090
JiangminExploit.ShellCode.ftc
eGambitUnsafe.AI_Score_100%
AviraTR/Crypt.ZPACK.Gen9
Antiy-AVLTrojan/Generic.ASMalwS.350BBD9
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.HV.R465391
Acronissuspicious
MAXmalware (ai score=81)
VBA32BScope.Trojan.Sabsik.FL
MalwarebytesMalware.AI.598294510
APEXMalicious
RisingExploit.Shellcode!8.2A (C64:YzY0OliWflAdonyj)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Zusy.412090?

Zusy.412090 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment