Malware

Zusy.484043 removal instruction

Malware Removal

The Zusy.484043 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.484043 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.484043?


File Info:

name: 76BEB8F75DA37D22DB1F.mlw
path: /opt/CAPEv2/storage/binaries/bcf9d0e3fa66629f39ff48f6041e66660dbb19e1e3e03fac404543766b48ec7f
crc32: 598EE1EB
md5: 76beb8f75da37d22db1f885112baf73c
sha1: ee692644566bddcc8b9a3be1dddddeb180f9c0b4
sha256: bcf9d0e3fa66629f39ff48f6041e66660dbb19e1e3e03fac404543766b48ec7f
sha512: 7c32f15ddb4b189accbaf6366bd4f60ec38c53dac40decb4df222cea323002236ea681fadeaaa17b646ebb653c30f1a944bf042dbc9b1c1cdf03c50556470306
ssdeep: 24576:Tm3ADi51GQRYXRKQFmKeGh6+Sut7kK3qD6E6l:ThyQKEH7vtl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17A555A01B6D3C0B3E54811B1195E47FD2A70E9384A244A8FF7E0EEEDFC63350AA5B659
sha3_384: cc72127b7bae157dd2f6d02ba434bfd83c99ed162c7dd354b5800ba903b0dfc208f81fda29fee212f27dcf0c0f4177e5
ep_bytes: 558bec6aff6878455100684cc7490064
timestamp: 2012-07-24 11:42:23

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Zusy.484043 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.484043
FireEyeGeneric.mg.76beb8f75da37d22
SkyhighBehavesLike.Win32.Generic.tm
McAfeeGeneric FakeAV.iv
MalwarebytesGeneric.Malware.AI.DDS
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_60% (D)
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Zusy.484043
SophosGeneric ML PUA (PUA)
F-SecureTrojan:W32/DelfInject.R
VIPREGen:Variant.Zusy.484043
Trapminesuspicious.low.ml.score
EmsisoftApplication.Generic (A)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.BSE.1L19CCX
WebrootW32.Meredrop.Gen
GoogleDetected
Antiy-AVLTrojan/Win32.FlyStudio.a
Kingsoftmalware.kb.a.980
XcitiumWorm.Win32.Dropper.RA@1qraug
ArcabitTrojan.Zusy.D762CB
MicrosoftTrojan:Win32/Emotet!ml
VaristW32/Trojan.GRW.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R609882
ALYacGen:Variant.Zusy.484043
MAXmalware (ai score=86)
Cylanceunsafe
RisingTrojan.Generic@AI.97 (RDML:WmkBNk2ZvimYxAsYQo9v+A)
MaxSecureDropper.Dinwod.frindll
BitDefenderThetaGen:NN.ZexaF.36738.tr0@aSDPcWdb
Cybereasonmalicious.4566bd
DeepInstinctMALICIOUS

How to remove Zusy.484043?

Zusy.484043 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment