Malware

How to remove “Zusy.456232”?

Malware Removal

The Zusy.456232 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.456232 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.456232?


File Info:

name: DCB3E709BD1159F34848.mlw
path: /opt/CAPEv2/storage/binaries/82a8f8b5f7da6032d1d7483be57ac992909ebf32874bf44cf3f23e2e3b63b5a9
crc32: CC638CDB
md5: dcb3e709bd1159f3484864f480616ec7
sha1: 0a79701fd8b01cb3172faa70a0ed70bcb3111ee0
sha256: 82a8f8b5f7da6032d1d7483be57ac992909ebf32874bf44cf3f23e2e3b63b5a9
sha512: b4d514ac530d233cf9eba00dbac3da0f5edf376bff547be09cf810e7bb17b0421ad5c557c3b857c94aedbe734f49512231631ed45b1e287273c7ba8029595ac9
ssdeep: 6144:55mWwcZuFleTFVHBGkJ9v9dHD/+Lu/UxQ8l9N:mWwcZuEBX7LHD2VQ8l9
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1A5544C1AB2A55010E6DEC5FF01EFDE788C3B6821A7F21394E28D9717561B15622BF0B3
sha3_384: 2828901d92fd457b5f726d3936c8e17fb080607e1e69800db5a568738be88aba20e0dd92e96fc2ec87605f92a2c875f4
ep_bytes: e8173c0000e9a4feffff3b0dfc1a4400
timestamp: 2023-04-03 07:23:39

Version Info:

Comments: Mathematicians protagonists dr clavicle mannerism mechanist
CompanyName: Munitions inorganic coldblooded
FileDescription: Starkest lusher pities sling acceptably affirmations
FileVersion: 3.190.147.3
InternalName: Limped cooking
LegalCopyright: Copyright © Liked regattas governed
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 3.190.147.3
Translation: 0x081a 0x081a

Zusy.456232 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 99)
FireEyeGeneric.mg.dcb3e709bd1159f3
McAfeeGenericRXVS-QE!DCB3E709BD11
MalwarebytesMalware.AI.4128013703
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 0059d50d1 )
K7AntiVirusTrojan ( 0059d50d1 )
BitDefenderThetaGen:NN.ZexaE.36132.rq2@ae8yDOpi
CyrenW32/Kryptik.JLA.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HSEV
APEXMalicious
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Variant.Zusy.456232
MicroWorld-eScanGen:Variant.Zusy.456232
AvastWin32:CrypterX-gen [Trj]
TencentMalware.Win32.Gencirc.10be8d4d
EmsisoftGen:Variant.Zusy.456232 (B)
F-SecureTrojan.TR/AD.RedLineSteal.tqqhn
VIPREGen:Variant.Zusy.456232
McAfee-GW-EditionGenericRXVS-QE!DCB3E709BD11
Trapminemalicious.high.ml.score
SophosTroj/Steal-DLK
IkarusTrojan.Win32.Crypt
GDataGen:Variant.Zusy.456232
AviraTR/AD.RedLineSteal.tqqhn
Antiy-AVLTrojan/Win32.Kryptik
ArcabitTrojan.Zusy.D6F628
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
MicrosoftTrojan:Win32/Redline.GHF!MTB
GoogleDetected
AhnLab-V3Trojan/Win.RedLine.R567736
VBA32BScope.Trojan.Sabsik.FL
ALYacGen:Variant.Zusy.456232
MAXmalware (ai score=80)
Cylanceunsafe
PandaTrj/GdSda.A
RisingBackdoor.Agent!8.C5D (TFE:5:4yrYLGsAGrH)
FortinetW32/Kryptik.HSEV!tr
AVGWin32:CrypterX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Zusy.456232?

Zusy.456232 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment