Malware

Zusy.481105 removal tips

Malware Removal

The Zusy.481105 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.481105 virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempted to write directly to a physical drive
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.481105?


File Info:

name: 790C3F5FA8FDF868C566.mlw
path: /opt/CAPEv2/storage/binaries/8111b4d6a0709d0e0daca5be1be49b839cb156b74bd226d7487090106ed579e5
crc32: D8BD3C4D
md5: 790c3f5fa8fdf868c566a1ed6afd3e30
sha1: bfdfbc22a005408ceca8911fcd2ab64bb11a88b0
sha256: 8111b4d6a0709d0e0daca5be1be49b839cb156b74bd226d7487090106ed579e5
sha512: 4b967157a0c40da6e1cd53c1f34bc1c4217e1eced2ef1f75a7669d8b85815fe1ef8c7c2fdabeb624999f54060acf5dd751601ca94490fd1ae10bf2efbe7728d4
ssdeep: 49152:HOGHqCwXuqDGwPefOVsYs8dFYvanGVhr7P+s8KuqGaX0ToIBAUZLYa:uGKCsuqDLKOV6CFYv4u7kJBAUZLZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B2E50202F392C5B7E1774230086E6F3ADA2ADD554B15CA8377A4FF4D1DB3390987612A
sha3_384: 4a11416f2f08089b90bfddadac00a69a9b94f202872f9b422ae20b38f48bce402a894a46ffc1615c63568f930974e17d
ep_bytes: 558bec6aff68e0456c0068f4c3460064
timestamp: 2012-04-28 04:33:08

Version Info:

FileVersion: 1.0.0.0
FileDescription: 安全稳定快速
ProductName: 腾讯最新穿越火线刷枪系统
ProductVersion: 1.0.0.0
CompanyName: 腾讯最新穿越火线刷枪系统
LegalCopyright: WwW.tyucf.Com
Comments: 腾讯最新穿越火线刷枪系统
Translation: 0x0804 0x04b0

Zusy.481105 also known as:

CyrenCloudW32/S-9a0e6078!Eldorado
BkavW32.AIDetectMalware
LionicTrojan.Multi.Generic.lwj0
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.481105
FireEyeGeneric.mg.790c3f5fa8fdf868
CAT-QuickHealRisktool.Flystudio.18826
SkyhighBehavesLike.Win32.Generic.vc
ALYacGen:Variant.Zusy.481105
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.FlyStudio.Vz94
K7AntiVirusTrojan ( 005246d51 )
AlibabaTrojan:Win32/Yakes.6987ccb9
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_70% (W)
ArcabitTrojan.Zusy.D75751
BitDefenderThetaGen:NN.ZexaF.36608.6s0@aCkSGvjb
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Cloud-9975987-0
KasperskyHEUR:Backdoor.Win32.Poison.pef
BitDefenderGen:Variant.Zusy.481105
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Variant.Zusy.481105
EmsisoftGen:Variant.Zusy.481105 (B)
F-SecureTrojan:W32/DelfInject.R
VIPREGen:Variant.Zusy.481105
TrendMicroTROJ_GEN.R002C0WIL23
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.QQpass
VaristW32/S-9a0e6078!Eldorado
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumWorm.Win32.Dropper.RA@1qraug
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Backdoor.Win32.Poison.pef
GDataWin32.Application.PSE.1OV7PVV
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R610330
McAfeeArtemis!790C3F5FA8FD
MAXmalware (ai score=80)
VBA32BScope.Trojan.Downloader
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002C0WIL23
RisingTrojan.Kazy!1.6838 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.PHP!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.2a0054
DeepInstinctMALICIOUS

How to remove Zusy.481105?

Zusy.481105 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment