Malware

Zusy.460370 removal guide

Malware Removal

The Zusy.460370 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.460370 virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.460370?


File Info:

name: B81329E5CBB194CCD2D2.mlw
path: /opt/CAPEv2/storage/binaries/39df30fdd54016173026838f8c0a9f8028a9f966729d62736d87ca47f7d0f8dc
crc32: 0D95CC76
md5: b81329e5cbb194ccd2d23297d44fb2b5
sha1: ac163b2bb1a95e70b12861b244c48b844876c444
sha256: 39df30fdd54016173026838f8c0a9f8028a9f966729d62736d87ca47f7d0f8dc
sha512: afbdb8fb3bb6745545caccc5253c3cfbb5af6010a56dbd57fd9f11c563304a7f462cc3ad4a5ab7fd1bb956ea4f03f8e51b7a67b789ffdf68c88ce1237de9c591
ssdeep: 6144:dCmSP6j6b+HdtH9Wd1yxBMfReMCDBNxkUDwK3bLKsnobns+NOYup6kN1e9jyh0XL:dW6u+Hdsy7MfcMexkA3XUnQ6kNyjq0XL
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T149D46A95FBC0EC97EA360679C9E7D356233CFAC04303DF579624A9326953BC1AE81612
sha3_384: 1462bbc06ab1c5800fe10f2b2848be9e4992f68d1039e0b7491d7a65986c5e3b7942eac8d6b13763060a9979fcfc62d8
ep_bytes: c7050021430000000000e9a1fcffff90
timestamp: 2023-04-16 15:57:57

Version Info:

0: [No Data]

Zusy.460370 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Convagent.4!c
MicroWorld-eScanGen:Variant.Zusy.460370
ClamAVWin.Malware.Dexter-9654223-0
FireEyeGeneric.mg.b81329e5cbb194cc
ALYacGen:Variant.Zusy.460370
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Poxters.Win32.319
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0049825e1 )
AlibabaTrojanDownloader:Win32/Graviwa.85d86c12
K7GWTrojan ( 0049825e1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Poxters.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Poxters.E
CynetMalicious (score: 99)
KasperskyTrojan-Downloader.Win32.Graviwa.ej
BitDefenderGen:Variant.Zusy.460370
NANO-AntivirusTrojan.Win32.Poxters.jvzbln
AvastWin32:Dexter-I [Trj]
TencentMalware.Win32.Gencirc.10bea397
EmsisoftGen:Variant.Zusy.460370 (B)
F-SecureTrojan.TR/ATRAPS.Gen2
DrWebTrojan.Packed.21724
VIPREGen:Variant.Zusy.460370
TrendMicroTROJ_GEN.R002C0DDK23
McAfee-GW-EditionRDN/Generic BackDoor
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Poxters
GDataGen:Variant.Zusy.460370
JiangminTrojanDownloader.Graviwa.h
AviraTR/ATRAPS.Gen2
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Poxters
ArcabitTrojan.Zusy.D70652
ZoneAlarmTrojan-Downloader.Win32.Graviwa.ej
MicrosoftPWS:Win32/Dexter.A
GoogleDetected
AhnLab-V3Trojan/Win.Dexter.C5415702
McAfeeRDN/Generic BackDoor
TACHYONTrojan/W32.Agent.619380
VBA32BScope.Trojan.Packed
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DDK23
RisingBackdoor.EclipseBot!1.C471 (CLASSIC)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Poxters.E!tr
AVGWin32:Dexter-I [Trj]
Cybereasonmalicious.bb1a95
DeepInstinctMALICIOUS

How to remove Zusy.460370?

Zusy.460370 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment