Malware

Should I remove “Ser.Zusy.4833”?

Malware Removal

The Ser.Zusy.4833 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Zusy.4833 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities to create a scheduled task
  • CAPE detected the shellcode get eip malware family
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Ser.Zusy.4833?


File Info:

name: AFD3F20669BC82F8EC00.mlw
path: /opt/CAPEv2/storage/binaries/60d1725c0d31c418ff8fca5e3a2b51a54a6efe32de452fd4d8d54f4213b1bbba
crc32: FB364A42
md5: afd3f20669bc82f8ec00fb13d4793f3e
sha1: 5fd9c6ff0dc752fa67fbcf75bfda26c1accb4516
sha256: 60d1725c0d31c418ff8fca5e3a2b51a54a6efe32de452fd4d8d54f4213b1bbba
sha512: a640ffffb5ec1e16d3ff111a33d80d88837833ca67e58d28b6173f4fd3e2f5db8c95549e2290e4939502a49efcc150b079351ff69b1ec31fa0ef2ee9ffb5d1a1
ssdeep: 24576:yAkWnvDVZZMv2jWlpc8xwQncoi68iuwwQ7TRHW/nSD0p5xFmZbmNrU0W0RV14Pt:yARnrVZZVjWpsoi68izlnR2/SD0xFmZj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C645333C1326D5A5DC2158B4809227A13EF8B5A9DB819007A98F9FE14BF42DE7337687
sha3_384: 41b764ec59c1a8a8b859fe3f16c485c78836a06127b56639738b8f7c269d40eb1e667c2c111f3353de4773f5a2006615
ep_bytes: 60e8000000005d81ed0600000081eda8
timestamp: 2024-01-24 07:18:15

Version Info:

0: [No Data]

Ser.Zusy.4833 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.VBKrypt.lwTF
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ser.Zusy.4833
FireEyeGeneric.mg.afd3f20669bc82f8
McAfeeArtemis!AFD3F20669BC
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaPacked:Win32/Enigma.bd7f049b
ArcabitTrojan.Ser.Zusy.D12E1
BitDefenderThetaGen:NN.ZexaF.36680.iHW@a4e8J4dk
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Enigma.AAF
APEXMalicious
ClamAVWin.Trojan.Scar-6903585-0
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Ser.Zusy.4833
SophosGeneric ML PUA (PUA)
VIPREGen:Variant.Ser.Zusy.4833
EmsisoftGen:Variant.Ser.Zusy.4833 (B)
IkarusTrojan.SuspectCRC
VaristW32/Threat-HLLIE-based!Maximus
Antiy-AVLTrojan[Packed]/Win32.Enigma
MicrosoftTrojan:Win32/Caynamer.A!ml
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataWin32.Trojan.PSE.1SA1MYQ
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R632639
VBA32BScope.Trojan.Bitrep
ALYacGen:Variant.Ser.Zusy.4833
MAXmalware (ai score=89)
DeepInstinctMALICIOUS
MalwarebytesGeneric.Malware.AI.DDS
ZonerProbably Heur.ExeHeaderL
SentinelOneStatic AI – Malicious PE
FortinetW32/Blacked.E!tr
Cybereasonmalicious.f0dc75
PandaTrj/Genetic.gen

How to remove Ser.Zusy.4833?

Ser.Zusy.4833 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment