Malware

What is “Zusy.419708”?

Malware Removal

The Zusy.419708 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.419708 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine Zusy.419708?


File Info:

name: 419837725BA02A284559.mlw
path: /opt/CAPEv2/storage/binaries/2f15a704c5f2b66bb68049a7e321175815ef3ac235af22c99f1c07e9194a27cd
crc32: 2D99F47A
md5: 419837725ba02a2845595d062d08a619
sha1: 8d6e40bc00a58da56c33faf507b8fce78a20fd41
sha256: 2f15a704c5f2b66bb68049a7e321175815ef3ac235af22c99f1c07e9194a27cd
sha512: d163622eb13cdf6f6aa0907695f74aabd7aace60d8f6d896fd7d20656c74a48022cd3eb33f2bb38117ddb2fe605793b00a6ef7ff09fc5197a9d9a864bb386b8c
ssdeep: 196608:z+lhq9kKXfca1/UUIYC65HGEN8TIUIhPwiquzdWGa:Ci5R1/iYC6VNczIhPXe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18AD6CF21B4A7E0A3D806F23C9CE68D651E1A4F5F372657C3746DBC65AF33CD026A2462
sha3_384: 7df202db17c34f922e7e4ebd0748e9eeaf21c53762d6ea0290354d66bdc05a29f39b38fedc5da82f813578e480caa7bb
ep_bytes: 558bec6aff68985b090168309d470064
timestamp: 2022-02-08 11:31:27

Version Info:

0: [No Data]

Zusy.419708 also known as:

BkavW32.AIDetect.malware1
LionicHeuristic.File.Generic.00×1!p
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.419708
FireEyeGeneric.mg.419837725ba02a28
ALYacGen:Variant.Zusy.419708
CylanceUnsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.c00a58
BitDefenderThetaGen:NN.ZexaF.34682.@tW@aSBxkopb
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:Trojan.Win32.Yakes.abeuu
BitDefenderGen:Variant.Zusy.419708
NANO-AntivirusTrojan.Win32.BlackHole.hqumcr
AvastWin32:Evo-gen [Trj]
Ad-AwareGen:Variant.Zusy.419708
EmsisoftGen:Variant.Zusy.419708 (B)
ComodoWorm.Win32.Dropper.RA@1qraug
VIPREGen:Variant.Zusy.419708
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
Trapminemalicious.high.ml.score
SophosGeneric PUA IN (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.11UD6H7
GoogleDetected
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Adware/Win.Cinmus.C5037999
VBA32Trojan.MSIL.Agent
MalwarebytesTrojan.MalPack.FlyStudio
TrendMicro-HouseCallTROJ_GEN.R002H0CIN22
RisingTrojan.Generic@AI.99 (RDML:6TkZPDJ4QZ6Xn9mjS2vagA)
IkarusTrojan.Black
FortinetW32/CoinMiner.65CA!tr
AVGWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Zusy.419708?

Zusy.419708 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment