Malware

Zusy.414139 malicious file

Malware Removal

The Zusy.414139 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.414139 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Portuguese (Brazil)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Zusy.414139?


File Info:

name: 0501365D9AC95CB71C0E.mlw
path: /opt/CAPEv2/storage/binaries/87644b2dbf3caea9efa25031d3a59db9eaf02cb15076a86fea77febedc37bcb8
crc32: 902CD660
md5: 0501365d9ac95cb71c0ea6a7d6b887ee
sha1: d16a34d94205e133f1deaa9d3efc72c55d0abea5
sha256: 87644b2dbf3caea9efa25031d3a59db9eaf02cb15076a86fea77febedc37bcb8
sha512: cdb2cc4131b7063af71637d0860c40aa7798a56091f836e54b3060b60bdf959add1e96ecc649a4ae9f0dbdc48ef2e9ecb24bb65e96b1defeb2beec52d1f767a0
ssdeep: 49152:/jUsLhxX3zWddISQw7dnhc3UlDa96jHJFALmd/M9MNi5YbNYu8b/ycsq3D+9TYTY:QsPzWs3Ca9myuM9eU/ycsSBDp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D9468E1A7284503AD4A70E368877D6A46D3BBA733E168D5737F81E4C8F36540393BA87
sha3_384: f942df7a89dd02e563111d71c572120d59fdb4822036ddae66d56b37361728998b3399e85e2c205a1c4489a69f0e7e94
ep_bytes: 558bec83c4f0b8f8828800e89496b6ff
timestamp: 2022-02-03 03:41:12

Version Info:

CompanyName: Mapphew Sunnybridgte
FileDescription: Mapphew Sunnybridgte
FileVersion: 23.55.21.66
InternalName: Mapphew Sunnybridgte
LegalCopyright: Mapphew Sunnybridgte
LegalTrademarks: Mapphew Sunnybridgte
OriginalFilename: Mapphew Sunnybridgte
ProgramID: Mapphew Sunnybridgte
ProductName: Mapphew Sunnybridgte
ProductVersion: 23.55.21.66
Comments: Mapphew Sunnybridgte
Translation: 0x0416 0x04e4

Zusy.414139 also known as:

LionicTrojan.Win32.Fragtor.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.414139
FireEyeGeneric.mg.0501365d9ac95cb7
ALYacGen:Variant.Zusy.414139
CylanceUnsafe
SangforTrojan.Win32.Sabsik.FL
K7AntiVirusTrojan-Downloader ( 0058da1d1 )
K7GWTrojan-Downloader ( 0058da1d1 )
BitDefenderThetaGen:NN.ZelphiF.34182.@V0@aqv!GNlk
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Delf_AGen.G
TrendMicro-HouseCallTROJ_GEN.R002H09B322
BitDefenderGen:Variant.Zusy.414139
EmsisoftGen:Variant.Zusy.414139 (B)
McAfee-GW-EditionBehavesLike.Win32.BadFile.th
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Delf
AviraTR/Redcap.vwbtq
MAXmalware (ai score=84)
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Zusy.414139
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4954548
McAfeeArtemis!0501365D9AC9
MalwarebytesTrojan.MalPack.DLF
AvastWin32:TrojanX-gen [Trj]
YandexTrojan.DL.Delf_AGen!2cjRyAsmkA8
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FPAH!tr
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Zusy.414139?

Zusy.414139 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment