Malware

Zusy.481727 information

Malware Removal

The Zusy.481727 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.481727 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Zusy.481727?


File Info:

name: EE860E3024CD967C1E55.mlw
path: /opt/CAPEv2/storage/binaries/d24f3797f2430417044de4888e09576dfe7585ca5eafa7a3d8cd1e308642f433
crc32: 6B1E0B00
md5: ee860e3024cd967c1e550738e2c50a14
sha1: a83157d73a218fd856dafbdda978ff37230bfe04
sha256: d24f3797f2430417044de4888e09576dfe7585ca5eafa7a3d8cd1e308642f433
sha512: dbb606142a9bc8b1acf2ebee91ec8dbcb329af65f7b27360d3509ed338792edb831465a49ba23f71c0539ff742fd7381f06be73b4542768d0578da6c8aff981d
ssdeep: 98304:lfgGFDrtinZWMaLoTcmwWQKdJKtZlXXL7CJfO8:JFfwZWN2cpWQKdJQZlvCP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D70633C623364002CED968F982BD50739F5D36BAE78206CFB9833639A5C7922C375971
sha3_384: e800ecd947e54417a431931214ce485a293ad6e3dffddb23d34277fdcc33d55942ae05399f7a890465aeb4aea5e82ea4
ep_bytes: 60be00508e008dbe00c0b1ff5789e58d
timestamp: 2024-04-16 17:52:29

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Zusy.481727 also known as:

BkavW32.AIDetectMalware
AVGWin32:CrypterX-gen [Trj]
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Zusy.481727
SkyhighBehavesLike.Win32.Generic.wc
Cylanceunsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZexaF.36802.XpKfaiohCehH
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
CynetMalicious (score: 100)
ClamAVWin.Malware.Trojanx-9951053-0
KasperskyVHO:Trojan.Win32.Convagent.gen
BitDefenderGen:Variant.Zusy.481727
AvastWin32:CrypterX-gen [Trj]
RisingTrojan.Yakes!8.430 (TFE:5:40EAeP6MV6V)
EmsisoftGen:Variant.Zusy.481727 (B)
VIPREGen:Variant.Zusy.481727
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.ee860e3024cd967c
SophosGeneric ML PUA (PUA)
IkarusTrojan.Crypt
VaristW32/Trojan.GRW.gen!Eldorado
Antiy-AVLTrojan[Packed]/Win32.FlyStudio
MicrosoftProgram:Win32/Wacapew.C!ml
ArcabitTrojan.Zusy.D759BF
ZoneAlarmVHO:Trojan.Win32.Convagent.gen
GDataWin32.Trojan.PSE.1BS1OJ0
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R598722
ALYacGen:Variant.Zusy.481727
MAXmalware (ai score=88)
MalwarebytesPUP.Optional.ChinAd
SentinelOneStatic AI – Malicious PE
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.PHP!tr
DeepInstinctMALICIOUS

How to remove Zusy.481727?

Zusy.481727 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment