Malware

Zusy.484716 (B) removal tips

Malware Removal

The Zusy.484716 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.484716 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.484716 (B)?


File Info:

name: 24A873EA075C2F9338F7.mlw
path: /opt/CAPEv2/storage/binaries/b5de3b2ca2b69b4ba9541d6d435299b0598bf8e495b8f52800ce029ae34836bb
crc32: 153EF694
md5: 24a873ea075c2f9338f7eb6c5523ea75
sha1: 70938c0d0582b2f4a7a9cdab8a362a24907d8efe
sha256: b5de3b2ca2b69b4ba9541d6d435299b0598bf8e495b8f52800ce029ae34836bb
sha512: 94e341e881e1a3e3e33a8e677cb94821a7c9ede393277384a5d550ea26d59afc73308732d3f58874106deb8050171bf1f0124e73ad69e054b5c64e9bd3599d3c
ssdeep: 98304:aqyOzzNH4I2wGW3a3HPHizthzj3C+xVwY+5cL6Zk550qp2mjTAzoV8+:3LzpHP26a3HPKnHC+xKYSclBZ03
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T138463319BFC5B3D8E85A5DF7D77C19AB01FBD7AD0280A79E6011FA8A76001810B3A477
sha3_384: f5b5cad292e76bf0f60bf2be5dbee2304f67211cc7dd3343c3562361842aa0edadb24e08fa5a6141f56ccb26a7ac2199
ep_bytes: b89817b7005064ff3500000000648925
timestamp: 2012-03-22 11:40:40

Version Info:

Comments: www.M6Dlq.com
CompanyName: M6反外挂引擎
FileDescription: M6反外挂登录器
FileVersion: 1.0.0.0
InternalName:
LegalCopyright: M6反外挂引擎 www.M6dlq.com
LegalTrademarks:
OriginalFilename:
PrivateBuild:
ProductName: M6反外挂引擎
ProductVersion:
SpecialBuild:
Translation: 0x0400 0x01b5

Zusy.484716 (B) also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Zusy.484716
ALYacGen:Variant.Zusy.484716
MalwarebytesMalware.Heuristic.1001
VIPREGen:Variant.Zusy.484716
Cybereasonmalicious.d0582b
BitDefenderThetaGen:NN.ZexaF.36662.@l0aaCw3ZGaH
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/FlyStudio.Packed.AE potentially unwanted
APEXMalicious
BitDefenderGen:Variant.Zusy.484716
EmsisoftGen:Variant.Zusy.484716 (B)
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.24a873ea075c2f93
SophosMal/EncPk-AQN
GDataGen:Variant.Zusy.484716
GoogleDetected
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.FlyStudio.a
ArcabitTrojan.Zusy.D7656C
CynetMalicious (score: 100)
McAfeeArtemis!24A873EA075C
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H09HS23
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/FlyStudio_Packed
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Zusy.484716 (B)?

Zusy.484716 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment