Malware

What is “Zusy.476146”?

Malware Removal

The Zusy.476146 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.476146 virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Zusy.476146?


File Info:

name: B054253BA47359D11EF1.mlw
path: /opt/CAPEv2/storage/binaries/0eb6248f76b9fff4dfaf626966a4d30ac3df2fb343b007f0c0e7e10f4a318b43
crc32: 6E0F3437
md5: b054253ba47359d11ef1327a22924248
sha1: 8163203902e71d6f52dcebcf4ae58892126f94f4
sha256: 0eb6248f76b9fff4dfaf626966a4d30ac3df2fb343b007f0c0e7e10f4a318b43
sha512: 132f058c956a5d6aeed85434498fd40a4484b6239be5a9143f5e2e2220aabe9abe889fde42e1c06e0d26faf93637dce733f491be46f124e3bb2cdee35c811183
ssdeep: 24576:bbWBgDAh8vETlnRrbuRv14t1bXR2BAGZahe2JSH0bW:mBIolx+14tNXIAYahezHr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DC152304F3A79B63F53B8372142B490523B41715B677EE0E0E4A55CE8B62397AB84BD3
sha3_384: 64c1de1dbddb510ba8eae31b66a48d4a01c6ed414c50592fec38223b4c45c8d181a7553cf4b940e0603cd0d16e393a19
ep_bytes: ff250020400000000000000000000000
timestamp: 2015-09-09 13:26:46

Version Info:

Translation: 0x0000 0x04b0
Comments: Liên Hệ 01667662226 để mua AutoUpdate Pro
CompanyName: Liên Hệ 01667662226 để mua AutoUpdate Pro
FileDescription: Liên Hệ 01667662226 để mua AutoUpdate Pro
FileVersion: 1.0.0.0
InternalName: AutoUpdate.exe
LegalCopyright: Liên Hệ 01667662226 để mua AutoUpdate Pro
OriginalFilename: AutoUpdate.exe
ProductName: Liên Hệ 01667662226 để mua AutoUpdate Pro
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Zusy.476146 also known as:

MicroWorld-eScanGen:Variant.Zusy.476146
ClamAVWin.Trojan.Generic-9801687-0
FireEyeGen:Variant.Zusy.476146
ALYacGen:Variant.Zusy.476146
SangforTrojan.Win32.Zusy.Vwm0
Cybereasonmalicious.ba4735
BitDefenderThetaGen:NN.ZemsilF.36318.2q0@aSd0yGk
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.MSIL.Bayrob.gen
BitDefenderGen:Variant.Zusy.476146
AvastWin32:TrojanX-gen [Trj]
TencentMalware.Win32.Gencirc.13ea32c1
EmsisoftGen:Variant.Zusy.476146 (B)
F-SecureTrojan.TR/Redcap.lfnmh
VIPREGen:Variant.Zusy.476146
McAfee-GW-EditionArtemis
Trapminemalicious.high.ml.score
IkarusTrojan-PWS.Win32.OnLineGames
GDataGen:Variant.Zusy.476146
AviraTR/Redcap.lfnmh
ArcabitTrojan.Zusy.D743F2
ZoneAlarmHEUR:Trojan.MSIL.Bayrob.gen
GoogleDetected
McAfeeArtemis!B054253BA473
MAXmalware (ai score=87)
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H07GH23
RisingTrojan.Convagent!8.12323 (CLOUD)
SentinelOneStatic AI – Suspicious PE
FortinetRiskware/Application
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Zusy.476146?

Zusy.476146 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment