Malware

Zusy.423176 (B) removal guide

Malware Removal

The Zusy.423176 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.423176 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Tries to unhook or modify Windows functions monitored by Cuckoo

How to determine Zusy.423176 (B)?


File Info:

name: 73AAC6935D7F4F35A508.mlw
path: /opt/CAPEv2/storage/binaries/5521e0e9bd5b821fe90fc3e03a0f71667eb17c982e4553b9fb0c410185317dbe
crc32: E3140833
md5: 73aac6935d7f4f35a5083cd85d2b28fb
sha1: 9406312994b35d2930910966c1e99f8cff6212d6
sha256: 5521e0e9bd5b821fe90fc3e03a0f71667eb17c982e4553b9fb0c410185317dbe
sha512: 7a4dc89da0b8af70ea1231245e7f04d9fc55ba1f4f04cd1bb83b2ef7cdf1a34603c66dd20540743acd03cbb0eb1a87873c0143ba663e58f01264e22830cc7dd1
ssdeep: 196608:iOXLhwnn1EGwbT1DndbMgBOdKTxJrtdlxXq14o:iJ2GqT1BQg8MPr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C18633B312A20586E5E28C39923BBCE471F316AB4782BC7D65D76CC139764B5F213983
sha3_384: 0bd4a597a3e55d02a15e456a5ee6f4f733c6453deddf88a60ba83b097534182ae7219aa4c8dc4fe123751cadd85b8d4f
ep_bytes: 6894d5fbc9e884fe0100f933daf7c760
timestamp: 2022-04-04 16:54:02

Version Info:

0: [No Data]

Zusy.423176 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.423176
FireEyeGeneric.mg.73aac6935d7f4f35
ALYacGen:Variant.Zusy.423176
CylanceUnsafe
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaGen:NN.ZexaF.34638.@xW@aGfigxb
CyrenW32/Trojan.HPB.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.VMProtect.ACR
ZonerProbably Heur.ExeHeaderL
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.423176
AvastWin32:MalwareX-gen [Trj]
Ad-AwareGen:Variant.Zusy.423176
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.Backdoor.rc
EmsisoftGen:Variant.Zusy.423176 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1210633
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Zusy.423176
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Trojan-gen.C4670559
APEXMalicious
RisingTrojan.Agent!8.B1E (TFE:dGZlOgVmG4p4Co/kjg)
IkarusTrojan.Win32.VMProtect
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VMProtect.ACR!tr
AVGWin32:MalwareX-gen [Trj]

How to remove Zusy.423176 (B)?

Zusy.423176 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment