Malware

Zusy.423348 (B) information

Malware Removal

The Zusy.423348 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.423348 (B) virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Zusy.423348 (B)?


File Info:

name: CBDA614004AA4A267BC8.mlw
path: /opt/CAPEv2/storage/binaries/3671df29cd456ba57211535587d95040ed324b8dc85fa34312ecd73fde7a663a
crc32: F629E8F8
md5: cbda614004aa4a267bc89f9d31ecde1f
sha1: 94f1132ffe3bd6c6db33c529177a6e2f186e26a5
sha256: 3671df29cd456ba57211535587d95040ed324b8dc85fa34312ecd73fde7a663a
sha512: f53d5f4e0b06fb78f878a6f1aacea930addd33cf40f8b36e0ed287bc5403f7fcae3315813683a9d73ba095244b45c17a0af72d972ad21f56347ab94b66c58065
ssdeep: 24576:I0aCQJOgkLzMIwC8QKTS1LQlAn9L5jTkLgXbs4boglG49q8qLEJK:IAQJOA8DnFxXb95lG49mLE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FC559E63F68280F1D31C213258AB5B35ADB497550E30CECBE7D8DE7A1D22A51A37B24D
sha3_384: c221f35eb487c937fd467d0f642f64734190d9b65f5a26617cf5dda86e1627f10b509903b626c6fd16341b6e64e6e744
ep_bytes: 558bec6aff6868fa4e0068e4bf4b0064
timestamp: 2021-05-11 01:53:55

Version Info:

FileVersion: 1.0.0.0
FileDescription: 2.2.2.2
ProductName: 1.0.0.1
ProductVersion: 1.0.0.0
CompanyName: by阿三
LegalCopyright: 印度阿三
Comments: 4.4.4.4
Translation: 0x0804 0x04b0

Zusy.423348 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.423348
FireEyeGeneric.mg.cbda614004aa4a26
CAT-QuickHealTrojanpws.Qqpass.16554
McAfeeGenericRXAA-AA!CBDA614004AA
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_90% (W)
CyrenW32/Backdoor.J.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Spy.KeyLogger.NUK
APEXMalicious
ClamAVWin.Malware.Ulise-9806872-0
KasperskyHEUR:Trojan.Win32.AddUser.gen
BitDefenderGen:Variant.Zusy.423348
NANO-AntivirusTrojan.Win32.Flyagent.iwfjpx
AvastWin32:Trojan-gen
TencentTrojan.Win32.Flyagent.16000183
Ad-AwareGen:Variant.Zusy.423348
SophosGeneric ML PUA (PUA)
DrWebTrojan.MulDrop18.60249
ZillyaTrojan.Flyagent.Win32.589
McAfee-GW-EditionBehavesLike.Win32.Generic.tm
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zusy.423348 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.423348
JiangminPacked.PePatch.oib
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C4599724
ALYacGen:Variant.Zusy.423348
TACHYONTrojan/W32.AddUser.1388544
MalwarebytesSpyware.KeyLogger
RisingTrojan.Flyagent!1.DAFB (CLASSIC)
YandexTrojan.AddUser!R4+9516a3Cg
IkarusTrojan-PSW.QQpass
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/KeyLogger.NUK!tr
BitDefenderThetaGen:NN.ZexaF.34742.ur0@aucHPTjb
AVGWin32:Trojan-gen
Cybereasonmalicious.ffe3bd
PandaTrj/GdSda.A

How to remove Zusy.423348 (B)?

Zusy.423348 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment