Malware

Zusy.413542 (B) information

Malware Removal

The Zusy.413542 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.413542 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Zusy.413542 (B)?


File Info:

name: EAB26C9DB85582251BC1.mlw
path: /opt/CAPEv2/storage/binaries/daff1f2c49c5f396c33a96a4bf78c03eebaeef55bf6f348319490faeaf32b549
crc32: 3D47C6E9
md5: eab26c9db85582251bc198e9b5a834df
sha1: 31111621808841fd0100a2c2cb78ab44c6259970
sha256: daff1f2c49c5f396c33a96a4bf78c03eebaeef55bf6f348319490faeaf32b549
sha512: f46b99a19e7e0b2e397d87b27d362ce510c72d73d818a8f776f3bc5abdc678ab6a3eb60e4ef08d1c04d9874e5b49bc2664a9047437c6dc4b9d96ed54e24619d5
ssdeep: 12288:Iy03gBCec6TSTki2n6xf5rEkKpOEr+yjIi:Iy0jpdXB1pE1FiaI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T108E4ADFB66578026C47A05738799FF10C262FB225D17492B523CDB2FF4212067A79A3E
sha3_384: 2ec8862e856503ee3c15cb3d159d227f2750dba62224ebcd9fbb63667e459ca6201c4cd64d0d721887cd2ab8126cf2e7
ep_bytes: f9eb16956e8a2c92ececb04c2c1e83d5
timestamp: 2022-01-21 10:09:09

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Zusy.413542 (B) also known as:

BkavW32.AIDetect.malware1
LionicHacktool.Multi.MultiPacked.x!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.413542
FireEyeGeneric.mg.eab26c9db8558225
ALYacGen:Variant.Zusy.413542
CylanceUnsafe
SangforTrojan.Win32.MultiPacked.gen
K7AntiVirusTrojan ( 0040f54a1 )
BitDefenderGen:Variant.Zusy.413542
K7GWTrojan ( 00539b2c1 )
CrowdStrikewin/malicious_confidence_60% (W)
CyrenW32/A-8128ee96!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastWin32:Pasta [Cryp]
CynetMalicious (score: 100)
KasperskyVHO:Trojan-PSW.Win32.QQPass.gen
AlibabaPacked:Win32/MultiPacked.0ea06332
NANO-AntivirusVirus.Win32.Agent.dvixmz
RisingPacker.Win32.Agent.f (CLASSIC)
Ad-AwareGen:Variant.Zusy.413542
SophosW32/Pidgeon-A
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
TrendMicroTROJ_GEN.R035C0PAR22
McAfee-GW-EditionBehavesLike.Win32.Virut.jc
EmsisoftGen:Variant.Zusy.413542 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Application.PUPStudio.A
JiangminPacked.Multi.jzw
Antiy-AVLTrojan[Packed]/Multi.MultiPacked
ArcabitTrojan.Zusy.D64F66
ZoneAlarmPacked.Multi.MultiPacked.gen
MicrosoftTrojan:Win32/Farfli.B!MTB
AhnLab-V3Packed/Win.MultiPacked.R467935
Acronissuspicious
McAfeeFlyagent.d
VBA32Trojan.Sabsik.FL
MalwarebytesPUP.Optional.ChinAd
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R035C0PAR22
TencentWin32.Packed.Multipacked.Anfm
MAXmalware (ai score=88)
eGambitUnsafe.AI_Score_99%
FortinetW32/CoinMiner.BELF!tr
BitDefenderThetaGen:NN.ZexaF.34182.Qy0@au@068mb
AVGWin32:Pasta [Cryp]
Cybereasonmalicious.db8558
Paloaltogeneric.ml
MaxSecureDropper.Dinwod.frindll

How to remove Zusy.413542 (B)?

Zusy.413542 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment