Malware

Zusy.412438 information

Malware Removal

The Zusy.412438 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.412438 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Zusy.412438?


File Info:

name: BFB677EE72A47E11CCE5.mlw
path: /opt/CAPEv2/storage/binaries/c0b129d94ed2c66d288339077ee16545af881ee265fa8e66a2e0d1f523c8a3d0
crc32: 819C251B
md5: bfb677ee72a47e11cce56fbd944c9630
sha1: 42d4717b3d4040c9abc3cf6b446225eaf6c12d46
sha256: c0b129d94ed2c66d288339077ee16545af881ee265fa8e66a2e0d1f523c8a3d0
sha512: d637537c883bf84b6972ca58f5da0e73e38aa5b499bb9597b548c31de81ad4149c097d03ab675d851e0dc04be765395b705f786884544f4615359648a033fb1f
ssdeep: 49152:HunwDO73BjqdH8SHh8nlkplRES9Z0pPvjbuUpn1o17TjU4KBw15V547:HMwaBWEkRES9ZYHrpn1ubUrU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T167363B327185643AD0662F364827B654583F7B212BD28C17AEB34B4C4F35682FA26F5F
sha3_384: acad489ceaf801ac4ce6060e76230082d6c4a5263351fd8544b3c78ff7da81f2386a86ed984a1066c2664f0834f7c6cc
ep_bytes: 558bec83c4f0b8a0547c00e8b0c7c3ff
timestamp: 2022-01-17 11:46:17

Version Info:

CompanyName: Sombare Box Shield
FileDescription: Sombare Box Shield
FileVersion: 454.5647.3465.123
InternalName: Sombare Box Shield
LegalCopyright: Sombare Box Shield
LegalTrademarks: Sombare Box Shield
OriginalFilename: Sombare Box Shield
ProgramID: Sombare Box Shield
ProductName: Sombare Box Shield
ProductVersion: 454.5647.3465.123
Comments: Sombare Box Shield
Translation: 0x0409 0x04e4

Zusy.412438 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.412438
SkyhighBehavesLike.Win32.Dropper.rh
McAfeeArtemis!BFB677EE72A4
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDownloader.DelfAGen.Win32.8
SangforTrojan.Win32.Delf_AGen.G
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan-Downloader ( 0058da1d1 )
K7AntiVirusTrojan-Downloader ( 0058da1d1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Delf_AGen.G
CynetMalicious (score: 100)
BitDefenderGen:Variant.Zusy.412438
AvastWin32:Trojan-gen
TencentWin32.Trojan.Redcap.Uylw
EmsisoftGen:Variant.Zusy.412438 (B)
F-SecureHeuristic.HEUR/AGEN.1326455
VIPREGen:Variant.Zusy.412438
FireEyeGeneric.mg.bfb677ee72a47e11
SophosMal/Generic-R
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Zusy.412438
GoogleDetected
AviraHEUR/AGEN.1326455
ArcabitTrojan.Zusy.D64B16
MicrosoftTrojan:Win32/Wacatac.B!ml
VaristW32/Delf.SC.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R469045
VBA32TScope.Trojan.Delf
ALYacGen:Variant.Zusy.412438
MAXmalware (ai score=85)
Cylanceunsafe
RisingTrojan.Generic@AI.100 (RDML:D67kQbVwjiWqbi56DX9EVg)
IkarusTrojan-Downloader.Win32.Delf
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FPAH!tr
BitDefenderThetaGen:NN.ZelphiF.36680.@V0@aKxFTlfi
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove Zusy.412438?

Zusy.412438 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment