Malware

Zusy.454467 removal

Malware Removal

The Zusy.454467 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.454467 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • Behavioural detection: Transacted Hollowing
  • Creates a copy of itself
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.454467?


File Info:

name: 7DDCCEC525E8BF6678C8.mlw
path: /opt/CAPEv2/storage/binaries/1997eca0026158256b58d583abe2c9eb06d5bc46d6b315c4e8a5c86521bb995c
crc32: AB9F99D2
md5: 7ddccec525e8bf6678c8f8ddaea1f3c8
sha1: e6b50a120bb46f9e56f1cdc2e612139b232941d6
sha256: 1997eca0026158256b58d583abe2c9eb06d5bc46d6b315c4e8a5c86521bb995c
sha512: 00b452c289431af6b0f4621737effbe9ea6d3642c84da24ca4deec8fb7e0d39999ebdc2fd0a460fb41486f29beb45a3b1dd933059cc726b95226c1ab9b9a6a07
ssdeep: 12288:zSnvQQqKF1KtLkkPMhjtEEHFyV+sqmqt+BtuvZL1e5/VU9iDvjjaZJ1Ltz:oYSF1KtoJjtsV+sqmqt+BtuvZL1e5/VG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T172A49E6FF34917B2468103B23A0F99C6BB2E9579236A85E0546CC01D2367E7C93BB7D4
sha3_384: 50952f57598bced3e3cb2debe79abdf4d839e70d1f254a0eb74e82df719d19b7448d7c0fd1ca76081f8e9f2b12ed7420
ep_bytes: 68000000005b83ec0489142409ff8b0c
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Zusy.454467 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
MicroWorld-eScanGen:Variant.Zusy.454467
SkyhighBehavesLike.Win32.VirRansom.gc
McAfeeGenericRXAA-FA!7DDCCEC525E8
MalwarebytesTrojan.MalPack
VIPREGen:Variant.Zusy.454467
SangforRansom.Win32.Save.a
K7AntiVirusTrojan ( 0056e8c71 )
BitDefenderGen:Variant.Zusy.454467
K7GWTrojan ( 0056e8c71 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36792.CmZ@aauGWzf
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HTAQ
APEXMalicious
ClamAVWin.Packed.Lazy-10001745-0
KasperskyHEUR:Trojan.Win32.Khalesi.pef
RisingTrojan.Copak!8.12117 (TFE:5:VirBWHbPg5E)
SophosTroj/Agent-BGUD
GoogleDetected
F-SecureTrojan.TR/Crypt.ZPACK.Gen
ZillyaTrojan.Kryptik.Win32.3400997
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.7ddccec525e8bf66
EmsisoftGen:Variant.Zusy.454467 (B)
IkarusTrojan.Win32.Injector
JiangminTrojan.Copak.auo
VaristW32/Kryptik.JDY.gen!Eldorado
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Kryptik
Kingsoftmalware.kb.a.999
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Zusy.D6EF43
ZoneAlarmHEUR:Trojan.Win32.Khalesi.pef
GDataWin32.Trojan.PSE.855VXQ
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.454467
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Wacatac
Cylanceunsafe
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.FFP!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.20bb46
AvastWin32:TrojanX-gen [Trj]

How to remove Zusy.454467?

Zusy.454467 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment