Malware

Zusy.480885 removal instruction

Malware Removal

The Zusy.480885 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.480885 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.480885?


File Info:

name: DAB8A10ADC709BAFFC49.mlw
path: /opt/CAPEv2/storage/binaries/2ac231131110a1317de92fa86999da77eb93a8e604823d24faf68fc6a4d81b3c
crc32: 912AEAE2
md5: dab8a10adc709baffc491e0d6a7743ae
sha1: df9ea850437a19a98d3db7080e13461ccdb25767
sha256: 2ac231131110a1317de92fa86999da77eb93a8e604823d24faf68fc6a4d81b3c
sha512: 0ca44a3841dbc2c493b2609e0b5b7eeb4c3b054bce53bbdde68689cbeccba133a136a63b70a7015abcf3f77649830897f932d80213b357df3ce5b2b21c1ab520
ssdeep: 3072:yhxzLUH2aIfbqX1ymEH7O7kTfJcjyvcR7Ym+uDWzK2Kne:yh5S2aYbqk7y+vcRSgd
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1DD147C28BB439962F8E59970FC71464A2735285D2FE4498AF37872FF331176B4C22396
sha3_384: de654b73cb29d9ef1c8f58c115ce30b178f3c172cd1b6e207445ade34b7a8f24ce6824beff980d154bac01c456583e1d
ep_bytes: e8de230000e9a4feffff558bec83ec08
timestamp: 2023-08-09 21:07:52

Version Info:

Comments: She tried to explain that love
CompanyName: There wasn't a set number
FileDescription: There wasn't less to
FileVersion: 4.332.765.877
InternalName: if you wanted to give
LegalCopyright: Copyright © That after a set amount
LegalTrademarks: given out it would all disappear
OriginalFilename: fuck off
ProductName: but it fell on deaf ears
ProductVersion: 4.332.765.877
Translation: 0x081a 0x081a

Zusy.480885 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.EasternRoppels.tsqK
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.480885
McAfeeArtemis!DAB8A10ADC70
Cylanceunsafe
ZillyaTrojan.GenKryptik.Win32.231110
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005a9f911 )
AlibabaTrojanSpy:Win32/Stealer.24e9fef4
K7GWTrojan ( 005a9f911 )
Cybereasonmalicious.0437a1
VirITTrojan.Win32.GenusT.DPNP
CyrenW32/Kryptik.KKK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HUIM
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Variant.Zusy.480885
NANO-AntivirusTrojan.Win32.Stealer.jzirpt
AvastWin32:PWSX-gen [Trj]
TencentMalware.Win32.Gencirc.13ed958b
EmsisoftGen:Variant.Zusy.480885 (B)
F-SecureTrojan.TR/AD.RedLineSteal.womfh
VIPREGen:Variant.Zusy.480885
TrendMicroTrojanSpy.Win32.REDLINE.YXDH2Z
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.dab8a10adc709baf
SophosTroj/Steal-DRU
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.480885
AviraTR/AD.RedLineSteal.womfh
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Kryptik
ArcabitTrojan.Zusy.D75675
ViRobotTrojan.Win.Z.Zusy.204800.AW
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
MicrosoftTrojan:Win32/Redline!ic
GoogleDetected
AhnLab-V3Trojan/Win.RedLine.R596627
VBA32BScope.TrojanPSW.Arkei
ALYacGen:Variant.Zusy.480885
MalwarebytesSpyware.RedLineStealer
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.REDLINE.YXDH2Z
RisingTrojan.Kryptik!8.8 (TFE:5:5F50dW1A8zD)
IkarusTrojan.Agent
MaxSecureTrojan.Malware.73793603.susgen
FortinetW32/Kryptik.HUIM!tr
BitDefenderThetaGen:NN.ZexaF.36722.mq0@aK7f6jfi
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Zusy.480885?

Zusy.480885 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment