Malware

What is “Zusy.424809 (B)”?

Malware Removal

The Zusy.424809 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.424809 (B) virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Zusy.424809 (B)?


File Info:

name: F8499F7F5F05B1128612.mlw
path: /opt/CAPEv2/storage/binaries/d244b88dd274ff732f161283bf5c8ada748f999f9643e93ab1ca69536fb2d4df
crc32: 72190229
md5: f8499f7f5f05b1128612582a79d71210
sha1: 7dc6a13ef22b17f429c594a671ee670b5c0c2b10
sha256: d244b88dd274ff732f161283bf5c8ada748f999f9643e93ab1ca69536fb2d4df
sha512: 787bf1b4a011ab95ac243264229197b7e8f85e552096d1aa3edd40cc03b8c2414031f5dd232b3ea73e2a6cc9e231844785cac875b5cc8a6555b471be4d1bd34a
ssdeep: 49152:/tIfoHUyK+oESHCJskNjs2yrWdyBRWS9G9Vq5uU+eX8X:1Ko0r+oESHexryDBRvG9Vq5lX8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DCE501057798CA27C4361A700896C7741A34BD615C22874FBBE87A1FEE732916F2A7CD
sha3_384: f8f4f4d8ab42d804a44e34cf76002e594b4d31990a8e6b7fe70d1f7c6ad29bfa3c64154fcf64bb6e11cc800cf1782e48
ep_bytes: 60be002053008dbe00f0ecff5783cdff
timestamp: 2022-06-09 06:51:30

Version Info:

FileVersion: 10.18.1.0
FileDescription: MySkin LOL
ProductName: MySkin
ProductVersion: 10.18.1.0
CompanyName: sky
LegalCopyright: sky的版权所有
Comments: MySkin LOL
Translation: 0x0804 0x04b0

Zusy.424809 (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Zusy.424809
FireEyeGeneric.mg.f8499f7f5f05b112
McAfeeArtemis!F8499F7F5F05
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
CyrenW32/VBInject.L.gen!Eldorado
tehtrisGeneric.Malware
APEXMalicious
ClamAVWin.Malware.Zusy-9951798-0
BitDefenderGen:Variant.Zusy.424809
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Zusy.424809
EmsisoftGen:Variant.Zusy.424809 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureHeuristic.HEUR/AGEN.1234502
McAfee-GW-EditionBehavesLike.Win32.Dropper.vh
Trapminemalicious.moderate.ml.score
SophosMal/Agent-AVP
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Zusy.424809
AviraHEUR/AGEN.1234502
ArcabitTrojan.Zusy.D67B69
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R444729
BitDefenderThetaGen:NN.ZexaF.34742.5o0@aWFcqUnb
ALYacGen:Variant.Zusy.424809
MAXmalware (ai score=82)
MalwarebytesMalware.AI.2388986513
RisingTrojan.Tiggre!8.ED98 (C64:YzY0OuupnDWusZ9u)
MaxSecureTrojan.Malware.180254171.susgen
FortinetW32/ULPM.16C0!tr
AVGWin32:Malware-gen
Cybereasonmalicious.f5f05b

How to remove Zusy.424809 (B)?

Zusy.424809 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment