Malware

About “Zusy.450767” infection

Malware Removal

The Zusy.450767 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.450767 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.450767?


File Info:

name: E6D90267629B22F33941.mlw
path: /opt/CAPEv2/storage/binaries/ff8d5d3467cfc9fecb512eafa9f2999d8534843c610944edcd141ced3634b66f
crc32: 6EA59301
md5: e6d90267629b22f339410c1c0cf9b92d
sha1: 26eeaeb0a8bbcf0d928872d52eb3346400f4530b
sha256: ff8d5d3467cfc9fecb512eafa9f2999d8534843c610944edcd141ced3634b66f
sha512: 370228bc7b21e076d45694caa49e581962791f9c386305838a45e837752b26f693aefa759f21e02ede736e0de3f047ec9c0ab2d8e0ff5554b8800cb54ee3fe4b
ssdeep: 3072:6G7J6w8EcwiWdoahH8ryvhVc77kJHQb5BEr+6MlQVRo9YCXtP8+vuOnG+6NzA/g:1d8AiWdo8Hphm3kC4xjRY8+vNnGBZr
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T14374DF373FC8B078D7EDCD745B663B3DAC1900E42E2B27CD62E42564825226C265B5BE
sha3_384: 0b223c907cde414c0ac8293875183d1b9f1b0ad968c95baa861e5e1b4e3596c487cb916d40d3f29cce1a92a236994d1a
ep_bytes: e8b4210000e9a4feffff8bff558bec8b
timestamp: 2023-02-17 18:59:15

Version Info:

Comments: Reply mrs embracing sputter
CompanyName: Sifted opposition hangers
FileDescription: Abundantly lending
FileVersion: 2.203.69.4
InternalName: Imbibers
LegalCopyright: Copyright © Unregarded sporty murderous disrupted microdensitometer intermittent
LegalTrademarks: Cessations belong tumbles
OriginalFilename: Paler
ProductName: Haircare
ProductVersion: 2.203.69.4
Translation: 0x081a 0x081a

Zusy.450767 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealer.12!c
MicroWorld-eScanGen:Variant.Zusy.450767
FireEyeGeneric.mg.e6d90267629b22f3
CAT-QuickHealTrojan.GenericRI.S30089813
ALYacGen:Variant.Zusy.450767
MalwarebytesGeneric.Crypt.Trojan.DDS
VIPREGen:Variant.Zusy.450767
K7AntiVirusTrojan ( 0059d3481 )
AlibabaTrojan:Win32/Redline.3dfdcd47
K7GWTrojan ( 0059d3481 )
BitDefenderThetaGen:NN.ZexaF.36250.vq2@aaxs!Eci
VirITTrojan.Win32.GenusT.EGJS
CyrenW32/ABRisk.LYBO-4040
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HSDM
APEXMalicious
CynetMalicious (score: 99)
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Variant.Zusy.450767
ViRobotTrojan.Win.Z.Zusy.352864.B
TencentMalware.Win32.Gencirc.10bdde6d
EmsisoftGen:Variant.Zusy.450767 (B)
F-SecureHeuristic.HEUR/AGEN.1362901
ZillyaTrojan.Stealer.Win32.51724
TrendMicroTrojanSpy.Win32.REDLINE.YXDDQZ
McAfee-GW-EditionGenericRXVN-QP!E6D90267629B
Trapminemalicious.high.ml.score
SophosTroj/Steal-DID
JiangminTrojanSpy.Stealer.agxv
AviraHEUR/AGEN.1362901
Antiy-AVLTrojan/Win32.Kryptik
ArcabitTrojan.Zusy.D6E0CF
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
GDataGen:Variant.Zusy.450767
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5384350
VBA32BScope.TrojanSpy.Stealer
MAXmalware (ai score=100)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXDDQZ
RisingBackdoor.Convagent!8.123DC (TFE:5:ldUL6VAvH1F)
IkarusTrojan.Win32.Redline
FortinetW32/Kryptik.HSEV!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Zusy.450767?

Zusy.450767 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment