Malware

Zusy.412195 information

Malware Removal

The Zusy.412195 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.412195 virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Zusy.412195?


File Info:

name: 88DBF2E57D87C47DE17F.mlw
path: /opt/CAPEv2/storage/binaries/68f0cc850181ff1ac59cf212917482ea11d75a51e77c9cb86ccd9d8f02b4a8a7
crc32: 37C01524
md5: 88dbf2e57d87c47de17f247a8b249399
sha1: 20fc896c0ace39b584d9ad66d99bed9f277d2431
sha256: 68f0cc850181ff1ac59cf212917482ea11d75a51e77c9cb86ccd9d8f02b4a8a7
sha512: a462e8f6599168685c6af8fcedaca97e44d26808295833362cc1435ad41967eea8e4f6fdd1aff84f3ec60924114d431812ec9df887ecc03fc8cfbaabe7c34d8b
ssdeep: 12288:RXw+zp/+TKv8NTZYWOdulplx38bQnlT18mrlWW/qE4pXTDiEmkInEGUo:RvgDNTZ1LT8snlT18mRWW/uDDSEG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16C254C23F6914437D07E1A38ECEB679DD82EBE012DEC98067BE83D4C4E396417925297
sha3_384: 63623ed2960561be620fa13288fe81a03c453252ce79ab06a414dff1eae188125908699a7ec546d36416f0e98a543f94
ep_bytes: 558bec83c4f0b83c794b00e808eef4ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Zusy.412195 also known as:

LionicTrojan.Win32.Zusy.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
McAfeeGenericRXRH-UC!88DBF2E57D87
CylanceUnsafe
SangforTrojan.Win32.Woreflint.A
K7AntiVirusTrojan ( 0058c8601 )
AlibabaTrojan:Win32/Generic.aac3938b
K7GWTrojan ( 0058c8601 )
CrowdStrikewin/malicious_confidence_60% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Delf.USY
APEXMalicious
ClamAVWin.Trojan.Agen-9846052-0
BitDefenderGen:Variant.Zusy.412195
MicroWorld-eScanGen:Variant.Zusy.412195
RisingStealer.QQpass!1.DB54 (CLOUD)
Ad-AwareGen:Variant.Zusy.412195
EmsisoftGen:Variant.Zusy.412195 (B)
TrendMicroTROJ_GEN.R002C0PAM22
FireEyeGeneric.mg.88dbf2e57d87c47d
SophosGeneric ML PUA (PUA)
Antiy-AVLTrojan/Generic.ASMalwS.35122CB
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
ArcabitTrojan.Zusy.D64A23
GDataGen:Variant.Zusy.412195
AhnLab-V3Trojan/Win.UC.C4926300
ALYacGen:Variant.Zusy.412195
MAXmalware (ai score=86)
MalwarebytesMalware.AI.4140547113
TrendMicro-HouseCallTROJ_GEN.R002C0PAM22
TencentMalware.Win32.Gencirc.11e4aeac
YandexTrojan.Delf!jD+3G0drKvg
IkarusTrojan.Win32.Delf
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Delf.USY!tr
BitDefenderThetaGen:NN.ZelphiF.34182.8GW@aGe9iVgb
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen

How to remove Zusy.412195?

Zusy.412195 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment