Malware

Zusy.484757 removal

Malware Removal

The Zusy.484757 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.484757 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.484757?


File Info:

name: B0E8504016823A336694.mlw
path: /opt/CAPEv2/storage/binaries/c701cddf32a2a17967fa4c2d4e1d60f15e55dc660a705244b2c8fd0e116782ce
crc32: A4CD181F
md5: b0e8504016823a3366945b7bb8a5c93e
sha1: 50d3241d486c28956e2059766dc322c86ffaa9fa
sha256: c701cddf32a2a17967fa4c2d4e1d60f15e55dc660a705244b2c8fd0e116782ce
sha512: 552ed308855d62751d4e03b12b0d3fb6a0352804a2b10efb2cc1d5e29d6808d4bcac1a19333fbcf3e874b18c5234283c56744b0be765d66057217b8fa7e579de
ssdeep: 24576:TFeTCPJ4lPUvGVdPwpv/s1THnvzUgKNaozC:ReT8JpvodYpMFvAtaozC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15E051204B1C0C1B3D477223645E5CB766A65397617A9AAC3FB861AF1AF303D0AB352CD
sha3_384: d377ebd52c23d94b0d2eb42cb4cfad9ade45197132daec0915c9248769422eb99c76dded917b881910e1adc7028b7199
ep_bytes: e8dd5b0000e9a4feffff6a0c68c81342
timestamp: 2009-09-20 11:43:57

Version Info:

Translation: 0x0000 0x04b0
Comments: q群18573707,79101251
CompanyName: 687130@qq.com
FileDescription: 一球成名浏览器
FileVersion: 1.0.4473.648
InternalName: 一球成名浏览器.exe
LegalCopyright: Copyright © 2011
LegalTrademarks: 687130@qq.com
OriginalFilename: 一球成名浏览器.exe
ProductName: 一球成名浏览器
ProductVersion: 1.0.4473.648
Assembly Version: 1.0.4473.648

Zusy.484757 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.484757
ClamAVWin.Malware.Score-6912404-0
FireEyeGen:Variant.Zusy.484757
Cylanceunsafe
Cybereasonmalicious.d486c2
BitDefenderThetaGen:NN.ZexaF.36350.Yq0@amOwF9e
VirITTrojan.Win32.Generic.MTO
APEXMalicious
BitDefenderGen:Variant.Zusy.484757
AvastFileRepMalware [Misc]
McAfee-GW-EditionBehavesLike.Win32.Injector.cc
Trapminemalicious.high.ml.score
SophosMal/Mdrop-BK
SentinelOneStatic AI – Suspicious PE
ViRobotWorm.Win32.Autorun.284737
GoogleDetected
McAfeeArtemis!B0E850401682
MAXmalware (ai score=84)
VBA32Trojan-Inject.Memtest
MalwarebytesMachineLearning/Anomalous.95%
RisingTrojan.Generic@AI.94 (RDML:2seuMEUxGuDZMsVnVyYDPw)
MaxSecureTrojan-Downloader.Agent.EDBQ
FortinetRiskware/MemDropper
AVGFileRepMalware [Misc]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Zusy.484757?

Zusy.484757 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment