Malware

About “Zusy.468898” infection

Malware Removal

The Zusy.468898 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.468898 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Zusy.468898?


File Info:

name: EADE1E82CB3A07419E44.mlw
path: /opt/CAPEv2/storage/binaries/5bec67fd864474f2b5c60e9a1e1948a184fd868dcaae45484ed6f77604609458
crc32: E349A711
md5: eade1e82cb3a07419e445dbb23cf9e85
sha1: 38676480f9a3f274d6167f7994ee6f952658645d
sha256: 5bec67fd864474f2b5c60e9a1e1948a184fd868dcaae45484ed6f77604609458
sha512: 96324be3bd6d82550844afc47ffd9da15d2890a12913903e3b0ca9eca1db8084d49426f1c15b40312d852c87bccf3354b292346ebd8666bec5c0d6ff0f248cbb
ssdeep: 384:izm/IE2q95IcIUuNBdw/5A/1mwnA3J3BXR+oGf7qWD+V0:izm195IcIjNQSkwy3BEP+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E6130782BB56CA81F09DA1B89883037A6283FD706E1077574564FF3B3EB31A05E91B71
sha3_384: 9b031a234f0a74d41ee792074123349a05aa0abaa2ef3068cbc003089a7ac5244056bd304e94b1a3bbe5d3e023e00da5
ep_bytes: 60be001041008dbe0000ffff5783cdff
timestamp: 2009-01-06 03:24:42

Version Info:

Translation: 0x0409 0x04b0
ProductName: Microsoft Windows
FileVersion: 1.00.0050
ProductVersion: 1.00.0050
InternalName: music
OriginalFilename: music.exe

Zusy.468898 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.468898
FireEyeGeneric.mg.eade1e82cb3a0741
SkyhighBehavesLike.Win32.Generic.pt
ALYacGen:Variant.Zusy.468898
MalwarebytesChir.Spyware.Infostealer.DDS
VIPREGen:Variant.Zusy.468898
SangforSuspicious.Win32.Save.a
BitDefenderGen:Variant.Zusy.468898
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaE.36792.cm0@aqWWy!gi
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
APEXMalicious
ClamAVWin.Malware.Genpack-6989317-0
AlibabaTrojan:Win32/Generic.fd3b8ec7
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.ULPM.Gen
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zusy.468898 (B)
IkarusTrojan.Crypt
GoogleDetected
AviraTR/Crypt.ULPM.Gen
VaristW32/Vilsel.H.gen!Eldorado
Kingsoftmalware.kb.b.936
MicrosoftTrojan:Win32/Caynamer.A!ml
XcitiumPacked.Win32.MUPX.Gen@24tbus
ArcabitTrojan.Zusy.D727A2
GDataGen:Variant.Zusy.468898
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Scar.C131205
Acronissuspicious
McAfeeGenericRXAA-AA!EADE1E82CB3A
MAXmalware (ai score=80)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H0CK623
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Malware-gen
Cybereasonmalicious.0f9a3f
AvastWin32:Malware-gen

How to remove Zusy.468898?

Zusy.468898 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment