Malware

Should I remove “Zusy.424862”?

Malware Removal

The Zusy.424862 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.424862 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Guard pages use detected – possible anti-debugging.
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Zusy.424862?


File Info:

name: AB7CD71016DE8B9147E7.mlw
path: /opt/CAPEv2/storage/binaries/7c12c0437cefbac4d80578f30ad87ab5034cc5764cd3ed2ab74dd6624026049e
crc32: C1BF485C
md5: ab7cd71016de8b9147e758e0edb0b1e6
sha1: e91452a5eb89c0b4f1fdb838eead229972163ad9
sha256: 7c12c0437cefbac4d80578f30ad87ab5034cc5764cd3ed2ab74dd6624026049e
sha512: 1ccc51e7fdd0f2e6781a3bd9ebbc12b86bc6f8c1e884f9e6e383d8465075724e34a6e0d56b28f6e538226eb72951edc39abae0606cbe22ec844efc0b5307a0fa
ssdeep: 12288:EZbDue+Ssg4u5SbsYAnhXwmdKdMzQqcW/LGqr6ht6k2vVcB:EZPue+Dg55QOhAq7zQqcW/L9r6/2tu
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C5E46C46FAA383F9C45B1C30209FA23EE6711A0DC1395F97EFF66D70B55EB01A505A0A
sha3_384: 8c2212b014d43c5120a64f9e75fdf862a37eab7f250f9bb1d7ec7ff8b0f8edcd52d6b38b231d2fc94e21d029fdebaad5
ep_bytes: c70570514a0001000000e9b1fcffff90
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Zusy.424862 also known as:

CynetMalicious (score: 100)
FireEyeGen:Variant.Zusy.424862
McAfeeGenericRXTJ-HJ!AB7CD71016DE
MalwarebytesMalware.AI.326103902
VIPREGen:Variant.Zusy.424862
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Filecoder.Hive_AGen.A
APEXMalicious
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderGen:Variant.Zusy.424862
MicroWorld-eScanGen:Variant.Zusy.424862
AvastWin32:RansomX-gen [Ransom]
Ad-AwareGen:Variant.Zusy.424862
EmsisoftGen:Variant.Zusy.424862 (B)
TrendMicroRansom.Win32.HIVE.SMYXCDA
McAfee-GW-EditionBehavesLike.Win32.Mytob.jh
GDataGen:Variant.Zusy.424862
JiangminTrojan.Generic.hidsm
AviraHEUR/AGEN.1250038
MAXmalware (ai score=87)
ArcabitTrojan.Zusy.D67B9E
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
MicrosoftRansom:Win64/Hive.E
AhnLab-V3Ransomware/Win.Ransom.R492086
VBA32BScope.TrojanRansom.Generic
ALYacGen:Variant.Zusy.424862
CylanceUnsafe
RisingRansom.Hive!8.12EEE (TFE:dGZlOgUr4Pr+JJ9SMA)
IkarusTrojan-Ransom.Hive
FortinetW32/Filecoder_Hive.A!tr.ransom
BitDefenderThetaGen:NN.ZexaF.34742.PKX@aarI@0j
AVGWin32:RansomX-gen [Ransom]
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Zusy.424862?

Zusy.424862 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment