Malware

What is “Zusy.481798 (B)”?

Malware Removal

The Zusy.481798 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.481798 (B) virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Zusy.481798 (B)?


File Info:

name: A6191B833A973DA3FEC5.mlw
path: /opt/CAPEv2/storage/binaries/35e6f8b857ebf7c1047801852b9fc24fe4bd24eebd34fffe5bc935332cbdd371
crc32: 847C89EE
md5: a6191b833a973da3fec52bd4a43b0cd6
sha1: 791d14a758c98199b86544e0f15b487c8db4e718
sha256: 35e6f8b857ebf7c1047801852b9fc24fe4bd24eebd34fffe5bc935332cbdd371
sha512: a1a281db925a93164144a32ebeb2b2c6353c8dd727085844333a3b1408f7d2df61398f6ac8897bcef03e182dfb8d7ed18d3b381ffe03eaa6cd03d1101e68f0ec
ssdeep: 393216:Xb3bPk5HPhJCIb3bPk5HY8ZeaRDOotj+eBLJ7XF:rWhLQ1tyeBLR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T153E6BE10F5C380B1DEE34574A296F35FA725F18281249DEAF99C1A85AF336914E2F31E
sha3_384: 918930a0cf0503173e24c861c1a1b2993623b0c4be862fc1a3cc2efe2668a491ae692e82183d681ad6741b113f1a2488
ep_bytes: 6a706820144000e8f701000033db538b
timestamp: 2004-08-04 06:02:34

Version Info:

CompanyName: Microsoft Corporation
FileDescription: CTF Loader
FileVersion: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
InternalName: CTFMON
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: CTFMON.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.1.2600.2180
OleSelfRegister:
Translation: 0x0409 0x04b0

Zusy.481798 (B) also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.481798
ClamAVWin.Malware.Generic-9839999-0
FireEyeGen:Variant.Zusy.481798
CAT-QuickHealTrojan.AgenFC.S20327787
ALYacGen:Variant.Zusy.481798
Cylanceunsafe
ZillyaDropper.Agent.Win32.468198
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005982a91 )
K7GWTrojan ( 005982a91 )
Cybereasonmalicious.33a973
CyrenW32/Olext.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.FIF
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Agentb.gen
BitDefenderGen:Variant.Zusy.481798
AvastWin32:DropperX-gen [Drp]
TencentTrojan-Dropper.MSIL.Agent.kc
SophosMal/Generic-R
F-SecureTrojan.TR/Patched.fkirm
DrWebWin32.Siggen.16
VIPREGen:Variant.Zusy.481798
McAfee-GW-EditionBehavesLike.Win32.RealProtect.tc
EmsisoftGen:Variant.Zusy.481798 (B)
IkarusTrojan-Dropper.MSIL.Agent
GDataWin32.Trojan.PSE.1JZ3HIF
AviraTR/Patched.fkirm
Antiy-AVLTrojan/Win32.Generic
ArcabitTrojan.Zusy.D75A06
ZoneAlarmHEUR:Trojan.Win32.Agentb.gen
MicrosoftTrojan:Win32/DllInject.EB!MTB
GoogleDetected
McAfeeArtemis!A6191B833A97
MAXmalware (ai score=83)
VBA32TScope.Trojan.MSIL
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/CI.A
YandexTrojan.Agent!AXRJ9YG7c6c
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/SPNR.15EG12!tr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Zusy.481798 (B)?

Zusy.481798 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment