Malware

Zusy.478099 removal tips

Malware Removal

The Zusy.478099 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.478099 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with Themida
  • Authenticode signature is invalid
  • Behavioural detection: Transacted Hollowing
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.478099?


File Info:

name: 55464C10481C45484D13.mlw
path: /opt/CAPEv2/storage/binaries/ac4622788a6234e52f4e679a09e4f827c7bb1e03e90ac8c4ee1032f0d4bfab03
crc32: EBC082CA
md5: 55464c10481c45484d13c9d1276bcf00
sha1: 629f259e2091979ee2e7492e9d8edaa2d73ec5e6
sha256: ac4622788a6234e52f4e679a09e4f827c7bb1e03e90ac8c4ee1032f0d4bfab03
sha512: 4ac55ad3cbeaa90fc885eb7f475c4b1817d750a2d75eb1baefdc3d325d5b53aba08b58b009d6c70f885d994993e3a741302d6fe8677b0a31b6c94fec9d5a59a1
ssdeep: 49152:ALTRj84rfvBYkMLUIobwmeq/0DrN37RPNw/Iq2d5BkIuGBz1DXs/X58gucn1Oa:AB84r3BEsbwmxW7JNdBh1gp8guE3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EFD533AB0900AEFAC973067A5A3B21256C393CD55B954487F09F3E559F2338D83F7898
sha3_384: 8045fffde9a62113471216172974743c3cdee1265aa45cc3b166526ac0dbd4e6fc4fd35f215582ea9cc0705f91181607
ep_bytes: e84b0100005389e3538b73088b7b10fc
timestamp: 2023-07-13 04:14:51

Version Info:

CompanyName: NCH Software
FileDescription: Express Burn Disc Burning Software
FileVersion: 12.00+
ProductVersion: 12.00+
ProductName: Express Burn
LegalCopyright: NCH Software
InternalName: ExpressBurn
OriginalFilename: ExpressBurn.exe
Translation: 0x0c09 0x04b0

Zusy.478099 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Zusy.478099
FireEyeGeneric.mg.55464c10481c4548
McAfeeArtemis!55464C10481C
SangforTrojan.Win32.Zusy.Vv45
CrowdStrikewin/malicious_confidence_90% (W)
ArcabitTrojan.Zusy.D74B93
BitDefenderThetaGen:NN.ZexaE.36318.YM2@a0yNEnei
ZonerProbably Heur.ExeHeaderL
APEXMalicious
BitDefenderGen:Variant.Zusy.478099
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
SophosGeneric ML PUA (PUA)
VIPREGen:Variant.Zusy.478099
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zusy.478099 (B)
Antiy-AVLTrojan/Win32.PossibleThreat
GDataGen:Variant.Zusy.478099
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Zusy.478099
MAXmalware (ai score=87)
Cylanceunsafe
RisingTrojan.Generic@AI.100 (RDML:aU3nl1zsbQc+YzDqZKzm1w)
FortinetW32/PossibleThreat
Cybereasonmalicious.e20919
DeepInstinctMALICIOUS

How to remove Zusy.478099?

Zusy.478099 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment