Malware

Zusy.412374 removal

Malware Removal

The Zusy.412374 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.412374 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • A process attempted to delay the analysis task by a long amount of time.
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • A process sent information about the computer to a remote location.
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings

How to determine Zusy.412374?


File Info:

name: 02F0087225451542CE32.mlw
path: /opt/CAPEv2/storage/binaries/30360e1c1c7f6e05733792f0662a615f44afe3ac3049e390d03b6a35feb86ba5
crc32: F9D193F1
md5: 02f0087225451542ce322cceb17bacf6
sha1: 315b6f2648c35ff8e40a66ab62e2caf7cd580db0
sha256: 30360e1c1c7f6e05733792f0662a615f44afe3ac3049e390d03b6a35feb86ba5
sha512: 0edac74d3830bdcd4ba8d022cf9c32f94bbe4b914748d598a3f48c3c08fa6d69cca6b5fc7dbe4696fa3542416ab76267c73851da7aa94c3d260ada7fc9af37cb
ssdeep: 12288:MOzxPbFC5Y+DBOTwBhHWXEvyu+mFwHjXQjgJq+XDX+LnYgzq+hbP3MoblyrYk8kE:nJZCvf7MjbXDX+Ljzqs9EVFFFE9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13F55F133B524ED33CC0702F2FF5E4A679D92E8904B5D12E39BE4665A90360E5C6F3A52
sha3_384: 8ff02f5940e1bd367c73f14365c63703d260efffb94311668dc378d17ead8898461103b1888323e6c3447689ec6a1b72
ep_bytes: e9d49e0100e9c1150200e949730200e9
timestamp: 2021-12-29 10:37:17

Version Info:

0: [No Data]

Zusy.412374 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Swizzor.kZ6h
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.412374
FireEyeGeneric.mg.02f0087225451542
McAfeeGenericRXAA-AA!02F008722545
CylanceUnsafe
SangforTrojan.Win32.Deyma.cml
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:Win32/Deyma.e522cff9
K7GWTrojan ( 0058d3e01 )
K7AntiVirusTrojan ( 0058d3e01 )
SymantecPacked.Generic.497
ESET-NOD32a variant of Win32/Kryptik.HOAR
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Deyma.cml
BitDefenderGen:Variant.Zusy.412374
AvastWin32:BotX-gen [Trj]
TencentMalware.Win32.Gencirc.10d0052d
Ad-AwareGen:Variant.Zusy.412374
EmsisoftGen:Variant.Zusy.412374 (B)
ZillyaTrojan.Inject.Win32.317387
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan.Win32.Generic
GDataGen:Variant.Zusy.412374
JiangminTrojan.PSW.Azorult.hvm
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1240830
MAXmalware (ai score=85)
Antiy-AVLTrojan[Banker]/Win32.Gozi
GridinsoftRansom.Win32.AzorUlt.sa
ArcabitTrojan.Zusy.D64AD6
ZoneAlarmTrojan-Downloader.Win32.Deyma.cml
MicrosoftTrojan:Win32/Mamson.A!ac
CynetMalicious (score: 100)
AhnLab-V3Infostealer/Win.CryptBot.C4923311
BitDefenderThetaGen:NN.ZexaE.34212.vvZ@am7uE4k
ALYacGen:Variant.Zusy.412374
VBA32BScope.TrojanDownloader.Deyma
MalwarebytesSpyware.PasswordStealer
TrendMicro-HouseCallTROJ_GEN.R002H0CB422
RisingBackdoor.Mokes!1.CECE (CLOUD)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.HOAR!tr
AVGWin32:BotX-gen [Trj]
PandaTrj/GdSda.A

How to remove Zusy.412374?

Zusy.412374 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment