Malware

What is “Zusy.414139 (B)”?

Malware Removal

The Zusy.414139 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.414139 (B) virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Portuguese (Brazil)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Zusy.414139 (B)?


File Info:

name: 9F1475EE2F578A2CE063.mlw
path: /opt/CAPEv2/storage/binaries/461c793a9f50a1c722d20e9d979c3cd9ed9cb1b07fbbdac2f0752b3106dd1922
crc32: F3555B28
md5: 9f1475ee2f578a2ce063f4081892ac24
sha1: 28e27bfe594fdd8b3818cbc352ec7db9c2ff25ad
sha256: 461c793a9f50a1c722d20e9d979c3cd9ed9cb1b07fbbdac2f0752b3106dd1922
sha512: 28ad8ce5357ae2d972711f345677658ff718654ae93b8772875e3f29c3090cc365cdab86f59717ebf9e34d4c3357e37b7336adab38a77e32681e2cca641d1a03
ssdeep: 49152:yCOYk1fhR48BwS6exdcNesqR+9JdH6sgvgPdBiJybRTDJdPDXQ/QG0Tk9TQTTFL6:yl9JR4xqRyJHriJiTaQbQsF7Wxnx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A3568E16B284A43AD0770F368837D7A4993B7F613E168D6B37F81E4C4F36680752A687
sha3_384: c60c3554061769645fc841ad9a8bd77fea13929201aa9a4221ed066ab6ca8396297633a507453bbb9af9c3d19f5f88e9
ep_bytes: 558bec83c4f0b858b08d00e8bc65b1ff
timestamp: 2022-02-03 03:41:47

Version Info:

CompanyName: Mapphew Sunnybridgte
FileDescription: Mapphew Sunnybridgte
FileVersion: 23.55.21.66
InternalName: Mapphew Sunnybridgte
LegalCopyright: Mapphew Sunnybridgte
LegalTrademarks: Mapphew Sunnybridgte
OriginalFilename: Mapphew Sunnybridgte
ProgramID: Mapphew Sunnybridgte
ProductName: Mapphew Sunnybridgte
ProductVersion: 23.55.21.66
Comments: Mapphew Sunnybridgte
Translation: 0x0416 0x04e4

Zusy.414139 (B) also known as:

LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.414139
FireEyeGeneric.mg.9f1475ee2f578a2c
McAfeeArtemis!9F1475EE2F57
CylanceUnsafe
SangforRiskware.Win32.Agent.ky
K7GWTrojan-Downloader ( 0056a18b1 )
BitDefenderThetaGen:NN.ZelphiF.34182.@V0@aOwwFigk
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Delf_AGen.D
TrendMicro-HouseCallTROJ_GEN.R002H09B422
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Zusy.414139
AvastWin32:TrojanX-gen [Trj]
EmsisoftGen:Variant.Zusy.414139 (B)
McAfee-GW-EditionBehavesLike.Win32.Virut.th
SophosMal/Generic-S
JiangminTrojan.Banker.Banbra.ekx
AviraTR/Redcap.uoikj
MAXmalware (ai score=89)
GridinsoftRansom.Win32.Sabsik.sa
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Zusy.414139
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R470584
ALYacGen:Variant.Zusy.414139
MalwarebytesTrojan.MalPack.DLF
RisingDownloader.Delf_AGen!8.1311B (CLOUD)
IkarusTrojan-Downloader.Win32.Delf
FortinetW32/GenKryptik.FPAH!tr
AVGWin32:TrojanX-gen [Trj]

How to remove Zusy.414139 (B)?

Zusy.414139 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment