Malware

How to remove “Zusy.434604 (B)”?

Malware Removal

The Zusy.434604 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.434604 (B) virus can do?

  • Unconventionial language used in binary resources: Korean
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Zusy.434604 (B)?


File Info:

name: EB5245A4AA56E6B4F89C.mlw
path: /opt/CAPEv2/storage/binaries/7aad2e467fd062577c9e780d21ab02a8e4929beb924a2fccca7f5a83b11621e9
crc32: BC56592C
md5: eb5245a4aa56e6b4f89c62a23487223d
sha1: 0b446ee3bf10736a0b0480f5b8fa92866e5c83f2
sha256: 7aad2e467fd062577c9e780d21ab02a8e4929beb924a2fccca7f5a83b11621e9
sha512: 5a4d9bd6d385eb2fd430874305b432206e02937a9fed3b2870bef22bca60a2a334ded3dd7423658e7687bb47d6f9852b489c74f192d96ef7452482d15f8e720d
ssdeep: 6144:YREBB6q1gBFJV6AvRqsf6YU+FM+3Yn/fCXjQGDq:sTq+Xxvo0U+d3s/fCX0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17464E026A6004869F71C0B36AA56F9E458498E7C54E8F61FF13CBE366D3218356B314F
sha3_384: 97adf5b6897d8b699a4cf5acfb2e8d12aebc38bfaf1bc4b5c7865a538c6f809324f3239328271114e3b17f179b392b72
ep_bytes: 60be003085008dbe00e0faff57eb0b90
timestamp: 2013-12-12 02:27:07

Version Info:

0: [No Data]

Zusy.434604 (B) also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Zusy.434604
FireEyeGeneric.mg.eb5245a4aa56e6b4
ALYacGen:Variant.Zusy.434604
Cylanceunsafe
VIPREGen:Variant.Zusy.434604
SangforTrojan.Win32.Save.a
Cybereasonmalicious.3bf107
Elasticmalicious (moderate confidence)
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.GenericML.xnet
BitDefenderGen:Variant.Zusy.434604
NANO-AntivirusTrojan.Win32.AVKill.jvqoxq
SUPERAntiSpywareTrojan.Agent/Gen-Urelas
AvastWin32:BackdoorX-gen [Trj]
EmsisoftGen:Variant.Zusy.434604 (B)
McAfee-GW-EditionBehavesLike.Win32.RealProtect.fh
Trapminemalicious.moderate.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.434604
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Zusy.D6A1AC
ZoneAlarmUDS:Trojan.Win32.GenericML.xnet
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Backdoor/Win32.Plite.R91390
McAfeeArtemis!EB5245A4AA56
MAXmalware (ai score=84)
MalwarebytesUrelas.Trojan.Downloader.DDS
IkarusTrojan.Win32.Urelas
FortinetW32/ULPM.16C0!tr
BitDefenderThetaGen:NN.ZexaF.36196.tmW@aG@JXClO
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Zusy.434604 (B)?

Zusy.434604 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment