Malware

About “Zusy.396480” infection

Malware Removal

The Zusy.396480 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.396480 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid

How to determine Zusy.396480?


File Info:

name: E26F45A6A4D8E77D1513.mlw
path: /opt/CAPEv2/storage/binaries/39dd7db35c50ebc1715481cebf089cae12873eb329469e550b519d50b5ba37e4
crc32: 3C85EB4E
md5: e26f45a6a4d8e77d15138523759af260
sha1: 03b8748ec5c61ef154c2dc3643f2404c3412db26
sha256: 39dd7db35c50ebc1715481cebf089cae12873eb329469e550b519d50b5ba37e4
sha512: 2401944dd0ca15d2e0a591ea48bcd5cce2206699541f7326c90a4ec0b91408c0e0358b0d9c12e931734cc3c6619660041701d84b43bd5fb99ffa5c3b0815c161
ssdeep: 98304:/b4Lg/gPnRB1nUbeDAdu4XHsgGpGUU7xqpb6Y5dB6LQcf2RsmnddA:j4ggPnRB1UbeDsuWGpGUU7xlY5dB6Qcz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14A46233356A91141E1F6CC3DC937BDD036F702ABCF82A4B964ABBDC125169E1D623943
sha3_384: 7e084e6eece953ca263024ea327e6fd2671f269c4bb3b28052793d0796271f7f874af79eed58da0d075feeaf3ce155e8
ep_bytes: 684a3305e2e80699fbff8b0e81c60400
timestamp: 2022-01-19 04:12:28

Version Info:

0: [No Data]

Zusy.396480 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Zusy.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.396480
FireEyeGeneric.mg.e26f45a6a4d8e77d
ALYacGen:Variant.Zusy.396480
CylanceUnsafe
SangforTrojan.Win32.Agent.aa
K7AntiVirusTrojan ( 7000001c1 )
K7GWTrojan ( 7000001c1 )
Cybereasonmalicious.ec5c61
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan-Downloader.Win32.Agent.xxzwfg
BitDefenderGen:Variant.Zusy.396480
AvastWin32:Malware-gen
TencentWin32.Trojan-downloader.Agent.Aihz
SophosMal/Generic-R + Mal/VMProtBad-A
TrendMicroTROJ_GEN.R002C0RAP22
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGen:Variant.Zusy.396480 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1200238
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.3515AE2
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmTrojan-Downloader.Win32.Agent.xxzwfg
GDataGen:Variant.Zusy.396480
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Agent.C4530080
McAfeeArtemis!E26F45A6A4D8
VBA32TScope.Malware-Cryptor.SB
TrendMicro-HouseCallTROJ_GEN.R002C0RAP22
RisingDownloader.Agent!8.B23 (CLOUD)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.34182.@FW@aKpmGShi
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Zusy.396480?

Zusy.396480 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment