Malware

Zusy.482711 removal guide

Malware Removal

The Zusy.482711 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.482711 virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Emumerates physical drives
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.482711?


File Info:

name: 3FA9662BB60AA0CB7FD4.mlw
path: /opt/CAPEv2/storage/binaries/80657da138057143c60c224917d76a32530ee61bcaba1ebc595c17d272524360
crc32: 6D6A6982
md5: 3fa9662bb60aa0cb7fd4f43315e15649
sha1: da5b64b29734de88ed272b05f6dbb032c3c09fec
sha256: 80657da138057143c60c224917d76a32530ee61bcaba1ebc595c17d272524360
sha512: 0cf84ba943035ba8d61cf1f710a11b33dfec9a9f097da46d81c8057a7bb2ea3e4e349fec93032435641d458fb23e314fcb5ad04e88449b06b42b829cc0f3c9a1
ssdeep: 49152:xge74uPDbnCYydjleqP1mYWdn5Qd7i9sfW5ZSoqzXfKEdO5H02vyEBk38N7SwlrD:xge75X+kqP1wdn5cO9yW2xdO5H0Oxtr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T193E58D6B7B05512AD15100397A3D9BA345ED6A727F29D1C3F7806E3924F07F2A638E0B
sha3_384: 2df7536dd63b8e180848c0bc8eaa8f76408f6c88215c19ab7850a0266eb36360c46e1a1c120294432bdbf6a4b0cb42c4
ep_bytes: e8cb040000e980feffff558bec5156ff
timestamp: 2018-08-16 04:09:06

Version Info:

0: [No Data]

Zusy.482711 also known as:

BkavW32.Common.A02C6665
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.482711
FireEyeGeneric.mg.3fa9662bb60aa0cb
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 005631a71 )
K7GWAdware ( 005631a71 )
Cybereasonmalicious.bb60aa
BitDefenderThetaGen:NN.ZexaF.36350.jBW@a8xdCgaj
CyrenW32/Softcnapp.DZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Softcnapp.BC potentially unwanted
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.482711
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Generic.e
EmsisoftGen:Variant.Zusy.482711 (B)
F-SecureHeuristic.HEUR/AGEN.1319114
ZillyaTrojan.Generic.Win32.1802522
McAfee-GW-EditionBehavesLike.Win32.Generic.wh
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.482711
JiangminTrojan.Generic.hrcmd
AviraHEUR/AGEN.1319114
XcitiumApplication.Win32.AdWare.Softcnapp.O@80ok4p
ArcabitTrojan.Application.Softcnapp.53
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftProgram:Win32/Wacapew.C!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R596592
Acronissuspicious
MAXmalware (ai score=86)
Cylanceunsafe
PandaTrj/Genetic.gen
APEXMalicious
RisingAdware.Downloader!1.BBEC (CLASSIC)
MaxSecureTrojan.Malware.7164915.susgen
FortinetRiskware/Softcnapp
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_100% (D)

How to remove Zusy.482711?

Zusy.482711 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment