Malware

Should I remove “Application.Zusy.481746”?

Malware Removal

The Application.Zusy.481746 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Zusy.481746 virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Application.Zusy.481746?


File Info:

name: 99326C155EC9F9D5CF1E.mlw
path: /opt/CAPEv2/storage/binaries/bf6cebd43b3affa4b2bc9de271e9ca3ccd7916ba5c5c54cdb4f347913a72fc65
crc32: EB92FFB4
md5: 99326c155ec9f9d5cf1e62950d65998c
sha1: e0b6e68862c7bc45513bc8b70efa6233ceeaac2a
sha256: bf6cebd43b3affa4b2bc9de271e9ca3ccd7916ba5c5c54cdb4f347913a72fc65
sha512: 82314de5a500ac2589ff4123d9c38a253554a6f4a39ae9e246ab77dec43d33c71d2264215635281a5d3635e38b10224882d1535b3183332a7e9fce3405332ade
ssdeep: 393216:2Q6YYJBjK1F5Jexa5iH1JmtyGkq6DmifGyYYDpUneQr:EKzexa5iUwq69pd0
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1C8E61233251280A2E0E99D7586373F247AF527311D75CC7AAFC8ACD12D62971EB1AB07
sha3_384: ca2a9aec29c0f32989ff775b8dc42df08b7d765f5f78cdfaf0b1dcf0ff5e16be96527b424efcc5d29d19fc832cb631b5
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2023-09-01 07:29:21

Version Info:

0: [No Data]

Application.Zusy.481746 also known as:

BkavW32.AIDetectMalware
LionicHacktool.Win32.Generic.lyGo
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Application.Zusy.481746
FireEyeGeneric.mg.99326c155ec9f9d5
SkyhighBehavesLike.Win32.Generic.tc
McAfeeArtemis!99326C155EC9
Cylanceunsafe
VIPREGen:Variant.Application.Zusy.481746
SangforTrojan.Win32.Save.BlackMoon
AlibabaRiskWare:Win32/PassUAC.5edec206
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.BlackMoon.A suspicious
APEXMalicious
ClamAVWin.Dropper.Tiggre-9845940-0
KasperskyHEUR:Exploit.Win32.UAC.gen
BitDefenderGen:Variant.Application.Zusy.481746
AvastWin32:Evo-gen [Trj]
RisingTrojan.MalCert!1.BD6A (CLASSIC)
SophosGeneric Reputation PUA (PUA)
DrWebBackDoor.Rootkit.15
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Application.Zusy.481746 (B)
IkarusTrojan.Crypt
GoogleDetected
VaristW32/Blackmoon.BA.gen!Eldorado
Antiy-AVLTrojan/Win32.Blamon.a
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Application.Zusy.D759D2
ZoneAlarmHEUR:Exploit.Win32.UAC.gen
GDataWin32.Trojan.PSE.1DPEYYJ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R597624
BitDefenderThetaGen:NN.ZedlaF.36744.@x7@a8pF5p
ALYacGen:Variant.Application.Zusy.481746
MAXmalware (ai score=79)
MalwarebytesMalware.AI.793340709
TencentMalware.Win32.Gencirc.13ee054c
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.74829239.susgen
FortinetW32/Blackmoon.D!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Application.Zusy.481746?

Application.Zusy.481746 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment