Malware

Should I remove “Zusy.442987”?

Malware Removal

The Zusy.442987 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.442987 virus can do?

  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Detects Bochs through the presence of a registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Accessed credential storage registry keys
  • Deletes executed files from disk
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Collects information to fingerprint the system
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.442987?


File Info:

name: DEF2195F4F77E483F840.mlw
path: /opt/CAPEv2/storage/binaries/ad1059f5f6b79ce5457ece42b94262216526c0738700b78c75977f425237fddc
crc32: CE827AF9
md5: def2195f4f77e483f8406d08cac1680a
sha1: 065ff8db7ea232acb2e312f75f1a41add17522bd
sha256: ad1059f5f6b79ce5457ece42b94262216526c0738700b78c75977f425237fddc
sha512: c541306bd318154b57c05c81573765958fca51bed96181f0ded103a4e648b32774135e66cbb93f7a82e99ea60599f0f18b010431eb09814f2f1142557b70c124
ssdeep: 24576:JCVYg0xcAbgifB4BvZpTK/kJ0EiEF+5ozolSHtn2mKgSNe5FOphi0joI19oghLNB:Jp/kJiEFsS0mK9WOzi0Q23
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14785BF13B191C0B2D129117215BA2B3AEA75B6128F35DED7E7D4CF692C322D1AB3720D
sha3_384: 2f99bdac5d4f314017110c66a786f8925e01f9fb16a141cc49b3b3867a271b05d53407e0063a2f7ce74c4805b84afccd
ep_bytes: 558bec6aff68b88d45006828c8440064
timestamp: 2023-03-03 18:00:12

Version Info:

0: [No Data]

Zusy.442987 also known as:

BkavW32.AIDetectNet.01
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.442987
ClamAVWin.Dropper.Tiggre-9845940-0
FireEyeGeneric.mg.def2195f4f77e483
CAT-QuickHealHacktool.Flystudio.16558
McAfeeArtemis!DEF2195F4F77
Cylanceunsafe
SangforTrojan.Win32.Save.BlackMoon
CrowdStrikewin/malicious_confidence_70% (W)
K7GWCryptoMiner ( 00593f811 )
K7AntiVirusCryptoMiner ( 00593f811 )
BitDefenderThetaGen:NN.ZexaF.36308.YnW@aasEAcm
CyrenW32/Coinminer.HG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/CoinMiner.CIB
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Blamon.gen
BitDefenderGen:Variant.Zusy.442987
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.11859f1f
EmsisoftGen:Variant.Zusy.442987 (B)
DrWebTrojan.Siggen19.61883
VIPREGen:Variant.Zusy.442987
McAfee-GW-EditionBehavesLike.Win32.Generic.th
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.CoinMiner
GDataGen:Variant.Zusy.442987
AviraTR/Spy.Gen
Antiy-AVLTrojan/Win32.FlyStudio.a
ArcabitTrojan.Zusy.D6C26B
MicrosoftTrojan:Win32/Sabsik.FL.A!ml
AhnLab-V3Trojan/Win.Generic.R560135
VBA32BScope.Trojan.CryptInject
ALYacGen:Variant.Zusy.442987
MAXmalware (ai score=88)
MalwarebytesFlyStudio.Trojan.MalPack.DDS
RisingDownloader.Snojan!8.ECDD (TFE:5:BauAJWfiyYT)
SentinelOneStatic AI – Malicious PE
FortinetW32/CoinMiner.WP!tr
AVGWin32:Evo-gen [Trj]

How to remove Zusy.442987?

Zusy.442987 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment