Malware

Zusy.641 removal guide

Malware Removal

The Zusy.641 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.641 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization

How to determine Zusy.641?


File Info:

name: DE4E28A4EF2F22CF7AB6.mlw
path: /opt/CAPEv2/storage/binaries/1984e2c2e5f8f0f7874111ef0283c36dcab99815f18f0975517c2fc2cc2d5c9b
crc32: 60C952BA
md5: de4e28a4ef2f22cf7ab6fc61cbb6f48e
sha1: 303e472ed485975313cec4ee39f53e8d071f1e0b
sha256: 1984e2c2e5f8f0f7874111ef0283c36dcab99815f18f0975517c2fc2cc2d5c9b
sha512: 1c4dada5e1c2c9d83503a3ae7f2a4aded0fe25b4df711dc565c7bba3ba661f41445adedc7208bab8a121cb96b698dbecae100c6a529d3aab9af65abb7af222d5
ssdeep: 3072:6JqeNmQ2T5UVGdIuNOQgL898ASOeQkp4oi2mC5Yq7Lt/cUbyxQLgtNYiL6Qoutay:reIQwOGdI639SY2mK0IyxQLMNbL6QoS7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C1141256EAA8C304E2F3513E16FFF7489834D0E5DE3A5C7BEF0429396C61329A606319
sha3_384: d9c181a1feaeed1efa01da955edf6dbacba8aa68f405c4892ba2d693981070ddb65f5eeddf45df7a8d17a12af6039d6e
ep_bytes: 60be003042008dbe00e0fdff5789e58d
timestamp: 2011-06-13 00:30:39

Version Info:

CompanyName: Quick Heal Technologies (P) Ltd.
FileDescription: Quick Heal AntiMalware
FileVersion: 6.0.0.1
InternalName: asmain.exe
LegalCopyright: © Quick Heal Technologies (P) Ltd. All rights reserved.
OriginalFilename: asmain.exe
ProductName: Quick Heal AntiVirus
ProductVersion: 13.00
Translation: 0x0409 0x04e4

Zusy.641 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.547
MicroWorld-eScanGen:Variant.Zusy.641
FireEyeGeneric.mg.de4e28a4ef2f22cf
CAT-QuickHealTrojanPWS.Zbot.Y
McAfeeArtemis!DE4E28A4EF2F
CylanceUnsafe
ZillyaTrojan.Menti.Win32.28638
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Cryptor.329b9d51
K7GWPassword-Stealer ( 003c6e581 )
K7AntiVirusPassword-Stealer ( 003c6e581 )
BitDefenderThetaGen:NN.ZexaF.34212.mm1@aSltM0fi
VirITTrojan.Win32.Generic.BJPO
CyrenW32/Zbot.DD.gen!Eldorado
SymantecPacked.Generic.350
ESET-NOD32Win32/Spy.Zbot.YW
TrendMicro-HouseCallTrojan.Win32.ZBOT.H
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Menti-35
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.641
NANO-AntivirusTrojan.Win32.Menti.kgqvg
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
TencentMalware.Win32.Gencirc.10ba4d94
Ad-AwareGen:Variant.Zusy.641
SophosMal/Generic-R + Mal/Zbot-EZ
ComodoTrojWare.Win32.Kryptik.ZSAA@4mdv0b
F-SecureTrojan-Spy:W32/Zbot.AVRO
VIPRETrojan.Win32.Reveto.D (v)
TrendMicroTrojan.Win32.ZBOT.H
McAfee-GW-EditionPWS-Zbot.gen.rc
EmsisoftGen:Variant.Zusy.641 (B)
GDataGen:Variant.Zusy.641
JiangminTrojan/Menti.qtz
WebrootW32.Infostealer.Zeus
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Win32.Unknown
ViRobotTrojan.Win32.A.Menti.201728.L
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Menti.R20280
Acronissuspicious
VBA32Malware-Cryptor.ImgChk
ALYacGen:Variant.Zusy.641
MAXmalware (ai score=99)
MalwarebytesMalware.AI.1986387590
APEXMalicious
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojanSpy.Zbot!gqo3q08+8jI
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.3615105.susgen
FortinetW32/Kryptik.ABC!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.4ef2f2
PandaGeneric Malware

How to remove Zusy.641?

Zusy.641 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment