Malware

What is “Zusy.483962”?

Malware Removal

The Zusy.483962 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.483962 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid

How to determine Zusy.483962?


File Info:

name: C6086C95B95BD0547963.mlw
path: /opt/CAPEv2/storage/binaries/b873695ebcb06896a595dc629ed547b08c5c840f5fa4259f598d48e84041d10c
crc32: 3B479F3C
md5: c6086c95b95bd054796360b044cc731a
sha1: ad15227d0b5d5c0126a12104e5a05b47db3a21c1
sha256: b873695ebcb06896a595dc629ed547b08c5c840f5fa4259f598d48e84041d10c
sha512: 8dc32665c301cd19ba98f9e0aa3bc52904d858bd1c59923eea1617060152807ef1cef9afd73ae869961bbf3559cac31c85947bab0f5322686903af118a6023ab
ssdeep: 1536:s1g39IFRu6L9o7wtmnrU97tzm5j1VA6Rxm9GEfwGDgUdCLNLz:d34toPrU9hy9Nm9GEfw9Bf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14B93087A7256CE10C67D2576C8CF412803FCAF832933DB596E9E260D65466F34D0AACE
sha3_384: 23c44abc9addf93c1b6cede0d199803f840562e52cd8830c4d59b608278252bdb8ac0fe0ceac7608c1e8dacf63c583d6
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-08-23 01:26:39

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 1.0.0.0
InternalName: XClient.exe
LegalCopyright:
OriginalFilename: XClient.exe
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Zusy.483962 also known as:

BkavW32.Common.8E6909DE
LionicTrojan.Win32.Generic.4!c
CynetMalicious (score: 100)
FireEyeGeneric.mg.c6086c95b95bd054
McAfeeArtemis!C6086C95B95B
Cylanceunsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/BruteForce.a7e480c2
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Agent.DWN
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.483962
MicroWorld-eScanGen:Variant.Zusy.483962
AvastWin32:BackdoorX-gen [Trj]
TencentWin32.Trojan.Generic.Gplw
EmsisoftGen:Variant.Zusy.483962 (B)
F-SecureHeuristic.HEUR/AGEN.1323362
VIPREGen:Variant.Zusy.483962
TrendMicroBackdoor.Win32.XWORM.YXDHYZ
McAfee-GW-EditionBehavesLike.Win32.Generic.nm
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.483962
AviraHEUR/AGEN.1323362
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Bladabindi!ml
AhnLab-V3Trojan/Win.Zapchast.C5475366
Acronissuspicious
ALYacGen:Variant.Zusy.483962
MAXmalware (ai score=86)
MalwarebytesBackdoor.XWorm
TrendMicro-HouseCallBackdoor.Win32.XWORM.YXDHYZ
IkarusHackTool.Win32.BruteForce
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.DWN!tr
BitDefenderThetaGen:NN.ZemsilF.36350.fq0@aqlBN2k
AVGWin32:BackdoorX-gen [Trj]
Cybereasonmalicious.d0b5d5
DeepInstinctMALICIOUS

How to remove Zusy.483962?

Zusy.483962 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment