Malware

Zusy.454623 (file analysis)

Malware Removal

The Zusy.454623 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.454623 virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.454623?


File Info:

name: 82D7F1E4BCBD92CBF395.mlw
path: /opt/CAPEv2/storage/binaries/a1fdd1caec3a52b77542a3a9fe9ab90967d9bcea94d7c9512fc17ae819ddf095
crc32: 6064D094
md5: 82d7f1e4bcbd92cbf39585cd267abdc0
sha1: 76b39ad310743a713ad80b322ac30b5dc331c9f4
sha256: a1fdd1caec3a52b77542a3a9fe9ab90967d9bcea94d7c9512fc17ae819ddf095
sha512: ac903dba52b322bc3cae03f6e70b3f30ee95b534214876f36585ab09ed36283766c311dd590c3240f4940cee405f77fbf0d6d02b520571e0f7d4c4b7ed64361a
ssdeep: 49152:OYJirE86CBlbsdBlBNsZ1O2ZlPdp82TlLJkA2A+QNi3f5XXEkfjO:VeE86CHKBlBNsZ1TlPdFTlLJkQ1Nuf5H
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A4759D217A519476C53B3231868EE3BAF2BD96314E79225722A14F382F354C3993C76F
sha3_384: 97eb601e969f7835a2f58d8bf0ee086a698796b42e336b598a7c53f1f9d15c5a8fa6e8b5f07cbbfa2cf15e437eb8031f
ep_bytes: e864960000e989feffff8bff558bec83
timestamp: 2023-03-23 08:10:00

Version Info:

0: [No Data]

Zusy.454623 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Zusy.454623
ALYacGen:Variant.Zusy.454623
MalwarebytesGeneric.Malware/Suspicious
ZillyaDownloader.Agent.Win32.507948
SangforDownloader.Win32.Zusy.Vah4
K7AntiVirusTrojan-Downloader ( 005a157f1 )
AlibabaTrojanDownloader:Win32/DropperX.b98b08e3
K7GWTrojan-Downloader ( 005a157f1 )
CyrenW32/ABRisk.IDRA-6592
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.GUL
APEXMalicious
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderGen:Variant.Zusy.454623
NANO-AntivirusTrojan.Win32.Generic.jvopde
AvastWin32:DropperX-gen [Drp]
RisingDownloader.Agent!1.E4E5 (CLASSIC)
EmsisoftGen:Variant.Zusy.454623 (B)
F-SecureTrojan.TR/Dldr.Agent.cnbcd
VIPREGen:Variant.Zusy.454623
McAfee-GW-EditionBehavesLike.Win32.Infected.th
FireEyeGen:Variant.Zusy.454623
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Agent
GoogleDetected
AviraTR/Dldr.Agent.cnbcd
MAXmalware (ai score=89)
Antiy-AVLTrojan[Downloader]/Win32.Agent
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Zusy.D6EFDF
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
GDataGen:Variant.Zusy.454623
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.R567333
McAfeeGenericRXAA-AA!82D7F1E4BCBD
Cylanceunsafe
PandaTrj/Chgt.AD
TencentMalware.Win32.Gencirc.118d7da2
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Agent.GTI!tr.dldr
BitDefenderThetaGen:NN.ZexaF.36318.LvW@aKSl!@ej
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Zusy.454623?

Zusy.454623 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment