Malware

Zusy.440559 (file analysis)

Malware Removal

The Zusy.440559 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.440559 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.440559?


File Info:

name: 5CC7785004CC442CAFDE.mlw
path: /opt/CAPEv2/storage/binaries/28282b2f3b2dacf80516eca4a55624ad382fa8c86ee8b7bb29be4897e7e6f458
crc32: 83668569
md5: 5cc7785004cc442cafdebee0685e1d52
sha1: bd7ce5c7c9ca623ad7aade8d89b9c5d2f826425f
sha256: 28282b2f3b2dacf80516eca4a55624ad382fa8c86ee8b7bb29be4897e7e6f458
sha512: b20fe67d952c782324b54f64f70a914970bb1280f6e39a897fb39ce6888b9da5567db7681ce89f98119fb960395880d3bd485d3bee20393bf58e98d34333b01c
ssdeep: 49152:JrJAkPGzMzEJhdgLkXIP9YuAjqVmAIRE147zpjPF5cRg4GrCZaaeajNw:JrJFGz5JhdgLk4nAqTI84BJ5c
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14C16BF12FF4180B2E5D2023511AB677E4E3DA9249B35C5D3D7D019AA8C316D2A73F3AE
sha3_384: f15bc803e2222a019afd24b2917f6d798da79191eb04fe628023dc5eb1bc998db2cb35a264e2f19d84acca425ebfdbc5
ep_bytes: e8620d0000e97afeffff8b4df464890d
timestamp: 2022-08-31 02:56:06

Version Info:

CompanyName:
FileDescription: Uninstaller
FileVersion: 1.0.0.1
ProductVersion: 1.0.0.1
InternalName: Uninst.exe
LegalCopyright: Copyright (C) 2021. All Rights Reserved
OriginalFilename: Uninst.exe
ProductName: Uninstaller
Translation: 0x0804 0x04b0

Zusy.440559 also known as:

BkavW32.AIDetectMalware
LionicRiskware.Win32.Zusy.1!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.440559
FireEyeGen:Variant.Zusy.440559
Cylanceunsafe
SangforTrojan.Win32.Save.a
BitDefenderThetaGen:NN.ZexaF.36318.@x0@aCVtirhj
CyrenW32/ABAdware.UCFU-3755
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/SuiXin.B potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Zusy.440559
ViRobotAdware.Suixin.4238848
AvastWin32:Malware-gen
EmsisoftGen:Variant.Zusy.440559 (B)
VIPREGen:Variant.Zusy.440559
GDataGen:Variant.Zusy.440559
WebrootW32.Trojan.GenKD
Antiy-AVLRiskWare/Perhaps.Suixin
ArcabitTrojan.Zusy.D6B8EF
GoogleDetected
VBA32BScope.TrojanPSW.RedLine
ALYacGen:Variant.Zusy.440559
MAXmalware (ai score=89)
MalwarebytesPUP.Optional.ChinAd.DDS
TrendMicro-HouseCallTROJ_GEN.R002H09JE22
RisingAdware.Agent!1.DD82 (CLASSIC)
YandexRiskware.Agent!A8pcjHbbW2E
IkarusPUA.SuiXin
MaxSecureTrojan.Malware.190479978.susgen
FortinetRiskware/Suixin
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Zusy.440559?

Zusy.440559 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment