Malware

Zusy.49407 removal guide

Malware Removal

The Zusy.49407 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.49407 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Executed a process and injected code into it, probably while unpacking
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

morphed.ru
amnsreiuojy.ru

How to determine Zusy.49407?


File Info:

crc32: 68D3FF46
md5: 581741c6c4d1cd0f01d526a09b3fae1b
name: 581741C6C4D1CD0F01D526A09B3FAE1B.mlw
sha1: fd69718b3d7c10021ae96fd101ea2c3e9b828914
sha256: 684db2508ad4ab5a9f11c31937986b682c65a9009a278450cb6b2fdc5610925e
sha512: 2a816cc10d8c7c07dca3666d882fbdeab7947e345674c0429d731fc52c1bfb747422195a45a8d2b64d9606a5c0048bbe0026c2bdad1463ca2b2c63abc0479dc0
ssdeep: 1536:RRkDnTSWukyxHE+JBWC7KnI4KTw+PGsvvkP:KnT6kyxdL9L0sGdP
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright Misejkaxa9 2013
InternalName: Ragiza
FileVersion: 2, 1, 3, 2
CompanyName: Hause
PrivateBuild: Kizbow
LegalTrademarks: Giokaxa9
Comments: Gezera
ProductName: Bigalov
SpecialBuild: Makanz
ProductVersion: 5, 1, 8, 4
FileDescription: Mikega
OriginalFilename: Magez
Translation: 0x0409 0x04b0

Zusy.49407 also known as:

BkavW32.FamVT.VebzenNJ.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.49407
FireEyeGeneric.mg.581741c6c4d1cd0f
CAT-QuickHealWorm.Gamarue.B
ALYacGen:Variant.Zusy.49407
CylanceUnsafe
VIPRETrojan.Win32.Inject.ea (v)
K7AntiVirusTrojan-Downloader ( 0056a5f91 )
BitDefenderGen:Variant.Zusy.49407
K7GWTrojan-Downloader ( 0056a5f91 )
Cybereasonmalicious.6c4d1c
TrendMicroWORM_GAMARUE.SMJ
BitDefenderThetaGen:NN.ZexaF.34634.emMfauqElhpO
SymantecPacked.Dromedan!gen7
TotalDefenseWin32/Gamarue.EBeAEVC
BaiduWin32.Trojan-Downloader.Wauchos.a
APEXMalicious
AvastWin32:Evo-gen [Susp]
ClamAVWin.Worm.Gamarue-6804112-0
KasperskyWorm.Win32.Bundpil.aws
NANO-AntivirusTrojan.Win32.Andromeda.csstqi
ViRobotTrojan.Win32.Agent.1689890[UPX]
RisingTrojan.Rimecud!8.60A (TFE:3:vt2YMmUZW5J)
Ad-AwareGen:Variant.Zusy.49407
SophosMal/Inject-EA
ComodoTrojWare.Win32.Kryptik.BBYD@4y3c16
F-SecureTrojan.TR/Dropper.Gen
DrWebBackDoor.Andromeda.178
InvinceaML/PE-A + Mal/Inject-EA
McAfee-GW-EditionGeneric.gl.gen.a
EmsisoftGen:Variant.Zusy.49407 (B)
IkarusTrojan-Downloader
JiangminTrojan.Generic.mqhi
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Dropper]/Win32.Injector
MicrosoftWorm:Win32/Gamarue.I
GridinsoftTrojan.Win32.Downloader.oa!s3
ArcabitTrojan.Zusy.DC0FF
SUPERAntiSpywareTrojan.Agent/Gen-Blocker
ZoneAlarmWorm.Win32.Bundpil.aws
GDataGen:Variant.Zusy.49407
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R67818
McAfeeGeneric.gl.gen.a
MAXmalware (ai score=80)
VBA32Backdoor.Androm
MalwarebytesTrojan.Downloader
ZonerTrojan.Win32.77507
ESET-NOD32Win32/TrojanDownloader.Wauchos.L
TrendMicro-HouseCallWORM_GAMARUE.SMJ
YandexTrojan.GenAsa!tycDiK8FwtU
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.BBYD!tr
AVGWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Zusy.49407?

Zusy.49407 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment