Malware

About “Zusy.466777” infection

Malware Removal

The Zusy.466777 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.466777 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.466777?


File Info:

name: 82BBA630853D6CE04AF2.mlw
path: /opt/CAPEv2/storage/binaries/be754df4f73831744c5a0d996eba0e5235ddbd15505ecf0980022725c183c333
crc32: 2F9F7B5D
md5: 82bba630853d6ce04af2dea2467f3d95
sha1: cf16e50c937df613705eaff4f06cdab49dc3d1d9
sha256: be754df4f73831744c5a0d996eba0e5235ddbd15505ecf0980022725c183c333
sha512: 68a939ededd71003b7ff6cde88f1ae2121883ec6dbab113cfbcfe2b03a81ebb86bea96a35c219a9c36a719596e5b32d67b284849fc076a1db754938a44c77c19
ssdeep: 98304:okRj9cmG6YcUc6g2beJ8E0KePJi9c0PKrRv+G9XnYBx05vIFbTK3xYStF0PjEKKE:oG9cmGm6HE0U9Lyo0XcaYK3xHz0PJKef
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F056338E815096B1E846AD34532FB8E1D9053C236F4278218D37C9E88E72FE2F9D5B57
sha3_384: 2e17e706996d1f7e84266aeaf629a0e6f0a5e937e1cc31cf9fa5db87f09073ce9fbbc195f9a7ebd7f6e1e3056446fc40
ep_bytes: 60be00c077008dbe0050c8ff5783cdff
timestamp: 2023-05-22 14:27:19

Version Info:

FileVersion: 13.7.20810.207
FileDescription: 电脑管家
ProductName: 电脑管家
ProductVersion: 13.7.20810.207
CompanyName: Copyright
LegalCopyright: Copyright 版权所有
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Zusy.466777 also known as:

BkavW32.AIDetectMalware
LionicAdware.Win32.Agent.2!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Zusy.466777
FireEyeGeneric.mg.82bba630853d6ce0
CAT-QuickHealTrojan.Generic.2919
McAfeeArtemis!82BBA630853D
MalwarebytesMalware.Heuristic.1003
ZillyaAdware.Agent.Win32.182006
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 005071f51 )
AlibabaAdWare:Win32/FlyStudio.84b9f068
K7GWAdware ( 005071f51 )
CrowdStrikewin/grayware_confidence_60% (W)
BitDefenderThetaGen:NN.ZexaF.36662.@pKfaKCy2VfH
CyrenW32/OnlineGames.HG.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
ClamAVWin.Malware.Trojanx-9951053-0
Kasperskynot-a-virus:AdWare.Win32.Agent.gen
BitDefenderGen:Variant.Zusy.466777
AvastWin32:TrojanX-gen [Trj]
SophosGeneric Reputation PUA (PUA)
VIPREGen:Variant.Zusy.466777
TrendMicroTROJ_GEN.R002C0WFH23
McAfee-GW-EditionBehavesLike.Win32.Backdoor.tc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zusy.466777 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1H6ZYWO
WebrootSystem.Monitor.Relytec/Supremte
GoogleDetected
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
ArcabitTrojan.Zusy.D71F59
ZoneAlarmnot-a-virus:AdWare.Win32.Agent.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C5169077
VBA32BScope.Downloader.Snojan
ALYacGen:Variant.Zusy.466777
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002C0WFH23
RisingAdware.Agent!8.71 (TFE:5:ATejHK9rKRD)
IkarusPUA.Virbox
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.PHP!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.c937df
DeepInstinctMALICIOUS

How to remove Zusy.466777?

Zusy.466777 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment