Malware

About “Zusy.76921 (B)” infection

Malware Removal

The Zusy.76921 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.76921 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Zusy.76921 (B)?


File Info:

name: AEF1B313DE6AE6BDF44B.mlw
path: /opt/CAPEv2/storage/binaries/1f7b70ca7f64551a7a8853cede1f54e30732ccc411464a4e0077c229425fe885
crc32: 32CF4862
md5: aef1b313de6ae6bdf44bde282a31e3b1
sha1: 84cafa8804c9a139b32cab69fd39e4c25d9f6c46
sha256: 1f7b70ca7f64551a7a8853cede1f54e30732ccc411464a4e0077c229425fe885
sha512: 48b5a5191684a81f03f5c302c09586a74e864457708843c13e835029815b32c6906dbeace2c80d4762d517007f7d377e54b8b2ef8b9c510f8a8a15d9b0eae08d
ssdeep: 384:LtetPbVS5/OcLmDqWPT+1o196cfys+xOXPYwPIWl3lXGV2xmzV777F7/m0N+GC4w:LWcYCW11azxOfZPIcWB73pxEv0Wq0yC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T154F22C57BA670A26C7AC09F180B3764047B4510B4612F7BF5EE87ADB7F42BD8A140EE4
sha3_384: 5263b270d65e45644cfc41738b045398e75bc06e19558ebc72691d2b89686219e66a26d1c540cbe27e44362d5a7c8ced
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-11-24 01:21:21

Version Info:

0: [No Data]

Zusy.76921 (B) also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericFC.S20328135
ALYacGen:Variant.Zusy.76921
CylanceUnsafe
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduMSIL.Backdoor.Bladabindi.a
CyrenW32/MSIL_Bladabindi.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Bladabindi.AS
APEXMalicious
ClamAVWin.Packed.Bladabindi-6862620-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.76921
NANO-AntivirusTrojan.Win32.Autoruner1.dbbxka
MicroWorld-eScanGen:Variant.Zusy.76921
AvastMSIL:GenMalicious-V [Trj]
TencentMalware.Win32.Gencirc.10b48560
Ad-AwareGen:Variant.Zusy.76921
EmsisoftGen:Variant.Zusy.76921 (B)
ComodoBackdoor.MSIL.Bladabindi.ASC@6cqkp9
DrWebWin32.HLLW.Autoruner1.63627
ZillyaTrojan.Bladabindi.Win32.28303
TrendMicroBKDR_BLADABINDI_EK0402F5.UVPM
McAfee-GW-EditionBehavesLike.Win32.Trojan.nm
FireEyeGeneric.mg.aef1b313de6ae6bd
SophosML/PE-A + Troj/Bbindi-W
IkarusTrojan.MSIL.Inject
GDataGen:Variant.Zusy.76921
AviraTR/Dropper.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.697468
ArcabitTrojan.Zusy.D12C79
MicrosoftBackdoor:MSIL/Bladabindi.AP
AhnLab-V3Trojan/Win32.ZBot.R136816
Acronissuspicious
McAfeeBackDoor-FDNN!AEF1B313DE6A
MAXmalware (ai score=89)
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.Bladabindi
TrendMicro-HouseCallBKDR_BLADABINDI_EK0402F5.UVPM
RisingBackdoor.Njrat!1.9E49 (CLASSIC)
YandexTrojan.Agent!PbYaTpYjVBs
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Bladabindi.Q!tr
BitDefenderThetaGen:NN.ZemsilF.34294.cmX@aywjdpd
AVGMSIL:GenMalicious-V [Trj]
PandaGeneric Malware
MaxSecureTrojan.Malware.300983.susgen

How to remove Zusy.76921 (B)?

Zusy.76921 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment