Malware

Zusy.413531 information

Malware Removal

The Zusy.413531 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.413531 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Macedonian
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Enumerates services, possibly for anti-virtualization
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Installs itself for autorun at Windows startup
  • Installs itself for autorun at Windows startup
  • CAPE detected the Tofsee malware family
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Zusy.413531?


File Info:

name: 95184AE5FAA2BD500FE5.mlw
path: /opt/CAPEv2/storage/binaries/f3a9578f88d159d3e88aadbbc0141fbe48b8b7d2a11ff6aaa7d0382c6760f668
crc32: 78A2023F
md5: 95184ae5faa2bd500fe590e42c83ddb4
sha1: 7a8c6123fe16176d4ee0695216e3c6e93a90e7b6
sha256: f3a9578f88d159d3e88aadbbc0141fbe48b8b7d2a11ff6aaa7d0382c6760f668
sha512: 5e53f5c53df817eb843df31fe44606393389ed51334c6d038093b1874f0372556589e28c6293c3b3937dca13c28891b95941b7f78f40ecffd6c226e96a84e1e9
ssdeep: 6144:3vtm/XnYdhxVdEc8p8p8p8p8p8p8p8p8p8p8p8p8p8p8p8p8p8p8p8p8p8p8p8pY:ftm/YDxbE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15EE6A68277F9D825F3F34A74957492D82A77FC97A835814EA0543B1B38B22C25DB1B23
sha3_384: fb98ea2cab64e60e1c4e8fe91585a81745785d24b103d3c7c69a0b978cebd557a2474eb8b370cd1b7ebc34e60b88338f
ep_bytes: e80f450000e978feffff8bff558bec81
timestamp: 2020-11-03 08:33:26

Version Info:

FileVers: 65.51.36.16
ProductVersa: 7.50.25.71
InternalName: peatemas
LegalCopyrighd: sharmir
Translation: 0x0169 0x0300

Zusy.413531 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Tofsee.m!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen16.39360
MicroWorld-eScanGen:Variant.Zusy.413531
FireEyeGeneric.mg.95184ae5faa2bd50
ALYacGen:Variant.Zusy.413531
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaRansom:Win32/StopCrypt.a75f9f36
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.3fe161
BitDefenderThetaGen:NN.ZexaF.34182.@t0@ae82YUaG
CyrenW32/Kryptik.GDH.gen!Eldorado
SymantecPacked.Generic.620
ESET-NOD32a variant of Win32/Kryptik.HODV
TrendMicro-HouseCallRansom_StopCrypt.R002C0DB322
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-9937750-0
KasperskyHEUR:Backdoor.Win32.Tofsee.pef
BitDefenderGen:Variant.Zusy.413531
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan.Kryptik.Hquy
SophosMal/Generic-S
ZillyaTrojan.Kryptik.Win32.3683581
TrendMicroRansom_StopCrypt.R002C0DB322
McAfee-GW-EditionBehavesLike.Win32.Generic.tt
EmsisoftGen:Variant.Zusy.413531 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.Tofsee.mewrh
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.35197DA
GridinsoftRansom.Win32.STOP.sa
MicrosoftRansom:Win32/StopCrypt.PAS!MTB
ZoneAlarmHEUR:Backdoor.Win32.Tofsee.pef
GDataGen:Variant.Zusy.413531
CynetMalicious (score: 100)
AhnLab-V3Ransomware/Win.Stop.R468727
McAfeePacked-GBE!95184AE5FAA2
TACHYONBackdoor/W32.Tofsee.13942784
VBA32Malware-Cryptor.2LA.gen
MalwarebytesTrojan.MalPack.GS
APEXMalicious
RisingBackdoor.Tofsee!8.1E9 (CLOUD)
YandexTrojan.Kryptik!rWfZ4mXXI0Q
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HODR!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Zusy.413531?

Zusy.413531 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment