Malware

How to remove “Zusy.437869 (B)”?

Malware Removal

The Zusy.437869 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.437869 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with Themida
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

How to determine Zusy.437869 (B)?


File Info:

name: BD4DCB7860D574E5BD84.mlw
path: /opt/CAPEv2/storage/binaries/d4a690ea5dae3a9b54a130db002510c15a367f0093f822ef7d8c93eebb7c63b7
crc32: D9A72EC2
md5: bd4dcb7860d574e5bd84bd4d448c9b68
sha1: 9e4412901b5d3f48ce048be87249da817de83c24
sha256: d4a690ea5dae3a9b54a130db002510c15a367f0093f822ef7d8c93eebb7c63b7
sha512: 7dd6c4f8c3e9a06907e6d12c4551171b5bdef89f5eaf068aae6586fae216855bd0a3288fd8646e5a935bf695be0c1cbd4f3c8b2f4cc46f5864224055efda6464
ssdeep: 98304:86xcEhpw2ePsJP1MqyC+Yu+NPaZVk9fB0rcTFdbrTNl5QQCp3NBqLs2CfnMSN4uC:8/QYPsLb+YurUZvRSBqLvyMSKut
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1946633511C179E9DD9E91072E57F8C0372C9223B7696A23211D8399F02F62BED939FE0
sha3_384: b8fb2deb37959005267205de18385c80be317c6308f51c09e21f5e4abcc76ec6e04809b3521a93d8f91a165e6d6520c3
ep_bytes: e84b0100005389e3538b73088b7b10fc
timestamp: 2022-08-30 07:47:13

Version Info:

0: [No Data]

Zusy.437869 (B) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.437869
FireEyeGeneric.mg.bd4dcb7860d574e5
CylanceUnsafe
VIPREGen:Variant.Zusy.437869
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.860d57
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyVHO:Trojan.Win32.Yakes.gen
BitDefenderGen:Variant.Zusy.437869
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:Evo-gen [Trj]
Ad-AwareGen:Variant.Zusy.437869
EmsisoftGen:Variant.Zusy.437869 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
GDataGen:Variant.Zusy.437869
AviraTR/Crypt.XPACK.Gen2
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/Sabsik.EN.D!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R520861
BitDefenderThetaGen:NN.ZexaF.34682.@BW@aunjyfi
ALYacGen:Variant.Zusy.437869
VBA32BScope.Trojan.Gatak
MalwarebytesMalware.Heuristic.1003
ZonerProbably Heur.ExeHeaderL
RisingTrojan.Generic@AI.100 (RDML:ky3pV2vNlDOgSeXJ+ZVUEg)
SentinelOneStatic AI – Malicious PE
AVGWin32:Evo-gen [Trj]

How to remove Zusy.437869 (B)?

Zusy.437869 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment