Malware

Should I remove “Zusy.481044”?

Malware Removal

The Zusy.481044 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.481044 virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Zusy.481044?


File Info:

name: A4CF3FC73DDD01A7D820.mlw
path: /opt/CAPEv2/storage/binaries/5467ec78adcd64a4a2a6b3ed6dd505f50c8cf74511cb2c6ca537f250259a10b1
crc32: 1E59A743
md5: a4cf3fc73ddd01a7d82038698b97f7ae
sha1: 2b51978e17e20a52645f69860ced4c59e5379f35
sha256: 5467ec78adcd64a4a2a6b3ed6dd505f50c8cf74511cb2c6ca537f250259a10b1
sha512: 97d87a18da111afb3775cf4974661734a174ef7404e0276dfec5729e7ce95ed0328704dcb07cefe9695c8c87de7e208d768e3f24d6f252f248af447b3d14d9f8
ssdeep: 196608:2I/OIFHzEje+bu4sithD2Xq/TKZVuIMuF9Od7G139vg:HOsES+b9si/C6/OVZOy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EE7633D90B54B2E9CDBE8E7AC906071E8574FD3B4090E62BFB8A376999327ED0C45701
sha3_384: b3233b60e4671131b79e7df720a10502da86b337241df5b6902b01676f65277ad10797c7dfcf9dcd26e6d4d6d251c5c5
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-08-06 00:01:15

Version Info:

0: [No Data]

Zusy.481044 also known as:

BkavW32.Common.D88C2C33
LionicTrojan.Win32.Remcos.4!c
MicroWorld-eScanGen:Variant.Zusy.481044
FireEyeGeneric.mg.a4cf3fc73ddd01a7
CAT-QuickHealBackdoor.MSIL
ALYacGen:Variant.Zusy.481044
MalwarebytesTrojan.Crypt.MSIL
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0059df7d1 )
AlibabaBackdoor:MSIL/Remcos.08734631
K7GWTrojan ( 0059df7d1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.AHUA
APEXMalicious
BitDefenderGen:Variant.Zusy.481044
F-SecureTrojan.TR/AD.RedLineSteal.zkvql
VIPREGen:Variant.Zusy.481044
TrendMicroTROJ_GEN.R011C0XHD23
Trapminemalicious.high.ml.score
SophosTroj/Remcos-ANY
IkarusTrojan.MSIL.Crypt
AviraTR/AD.RedLineSteal.zkvql
MAXmalware (ai score=85)
Antiy-AVLTrojan/MSIL.Kryptik
ArcabitTrojan.Zusy.D75714
GDataGen:Variant.Zusy.481044
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C5433967
BitDefenderThetaGen:NN.ZemsilF.36722.@p0@aSFADtni
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R011C0XHD23
TencentMalware.Win32.Gencirc.10bf2599
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.73696032.susgen
FortinetMSIL/Kryptik.AHUA!tr
Cybereasonmalicious.e17e20
DeepInstinctMALICIOUS

How to remove Zusy.481044?

Zusy.481044 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment