Malware

Zusy.452153 (file analysis)

Malware Removal

The Zusy.452153 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.452153 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Saami
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.452153?


File Info:

name: A2389B490DB029957C7A.mlw
path: /opt/CAPEv2/storage/binaries/b663fd624820be2417c7252aac74fb054f04fad76aff8cd82f624bc43dd440fb
crc32: C4D9B72C
md5: a2389b490db029957c7a571d7858d21b
sha1: 4eaf0f744ac9fab48d89259ee51ffb13534631ed
sha256: b663fd624820be2417c7252aac74fb054f04fad76aff8cd82f624bc43dd440fb
sha512: d38a46a900c7df0b6b5398476b498db12d5e24217f337cc332741b37b4a55853911194012694eeacbdc98b7d93be80dbcccea6b961bcb9beeb70b3fd589e4279
ssdeep: 6144:uMqXHaObLblB78p5m7H0D3l/5c+OppjOltN/MIcaoKaWgF0C0K:uMGHbbD7QIO5YpNOlUIh9aWgFHn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B554E01172F1D435E1F319702A36D3A4173BB8222E75E19F3254AAAE5DF26C08A76363
sha3_384: d572855149903c0fb7d5e824ed7b41315a4136008cb0f80be6d42888d2ce415fb59169e428d608e2a0560ba2ba54ca69
ep_bytes: e893470000e989feffff2da403000074
timestamp: 2022-07-07 22:25:21

Version Info:

CompanyName: Furious
FileDescription: WholeSheet
FileVersion: 25.71.48.45
InternalName: GorgerousVar.exe
LegalTrademarks1: Coordinator inc.
OriginalFilename: pskodkfgnosfd.exe
Translation: 0x4042 0x0564

Zusy.452153 also known as:

BkavW32.AIDetectNet.01
MicroWorld-eScanGen:Variant.Zusy.452153
FireEyeGeneric.mg.a2389b490db02995
Cylanceunsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005690671 )
K7GWTrojan ( 005690671 )
Cybereasonmalicious.44ac9f
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Backdoor.Win32.Mokes.gen
BitDefenderGen:Variant.Zusy.452153
AvastDropperX-gen [Drp]
TencentTrojan-Ransom.Win32.Stop.gen
SophosML/PE-A
BaiduWin32.Trojan.Kryptik.jm
McAfee-GW-EditionBehavesLike.Win32.Lockbit.dc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Jaik.127078 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.452153
MAXmalware (ai score=84)
ArcabitTrojan.Jaik.D1F066
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
RisingTrojan.Generic@AI.100 (RDML:mFv5M0pVSwZjODxCljzHVg)
IkarusTrojan.Win32.Crypt
AVGDropperX-gen [Drp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Zusy.452153?

Zusy.452153 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment