Malware

How to remove “Zusy.435211”?

Malware Removal

The Zusy.435211 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.435211 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Deletes executed files from disk

How to determine Zusy.435211?


File Info:

name: C7CB95308342F45FAAF5.mlw
path: /opt/CAPEv2/storage/binaries/115e4fa417ea7c51da7d151e939f7ff1b103bba644451fdabafaad99e77efaf0
crc32: 87F5068C
md5: c7cb95308342f45faaf51c7f09e33b4f
sha1: d9f56df6b276a4c8b375119081d34324aa441cfa
sha256: 115e4fa417ea7c51da7d151e939f7ff1b103bba644451fdabafaad99e77efaf0
sha512: 2544584514bc253808588cb1c2619b97aac4d1210d36b44ac829b7c384cc5492397577fb92c5814c0b25276083cc3e04a58a65797493378abc8cd221f0d9e38c
ssdeep: 49152:tBuZrEUAplvxV8QicaXiYHn55DdN7POGjR:7kLsxTI55ljR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C6A5D03FF268A53EC46A1B3245B38220997BBA61781A8C1F47FC344DCF765601E3B656
sha3_384: 82ccaa11c99e31319cfdcc36e55e54805711464b86c68cd8aa5f5273df666a0303e96786c653f8be6d4579137a397eb2
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2022-04-14 16:10:23

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: instaalleer Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: instaalleer
ProductVersion: 100.101.05
Translation: 0x0000 0x04b0

Zusy.435211 also known as:

Elasticmalicious (moderate confidence)
CynetMalicious (score: 100)
VIPREGen:Variant.Zusy.435211
K7AntiVirusTrojan ( 00596a771 )
BitDefenderGen:Variant.Zusy.435211
K7GWTrojan ( 00596a771 )
ESET-NOD32a variant of Win32/GenKryptik.FYMJ
KasperskyUDS:Trojan-Downloader.Win32.Satacom.gen
MicroWorld-eScanGen:Variant.Zusy.435211
AvastWin32:Trojan-gen
RisingTrojan.Generic@AI.94 (RDML:57+UcNnbJ64I18EDoKy95Q)
EmsisoftGen:Variant.Zusy.435211 (B)
F-SecureHeuristic.HEUR/AGEN.1251348
FireEyeGen:Variant.Zusy.435211
IkarusTrojan-Dropper.Win32.Agent
GDataGen:Variant.Zusy.435211
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1251348
ArcabitTrojan.Zusy.D6A40B
MicrosoftPUA:Win32/Pearfoos.B!ml
AhnLab-V3Trojan/Win.Sabsik.R509967
ALYacGen:Variant.Fragtor.127943
MAXmalware (ai score=87)
MalwarebytesMalware.AI.3255993480
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Trojan-gen

How to remove Zusy.435211?

Zusy.435211 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment