Malware

Zusy.485756 removal instruction

Malware Removal

The Zusy.485756 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.485756 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with Themida
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Zusy.485756?


File Info:

name: 1443250BFF51BFBAC281.mlw
path: /opt/CAPEv2/storage/binaries/a48d01447dd0e56edd0abe0be424aa5adf0c30d52e74b66e75d45ea84e3cf3d3
crc32: F5E43EEF
md5: 1443250bff51bfbac281b9b8fba29a3c
sha1: 50fd514282720d63c099d08bcd1853b8e1ab0a16
sha256: a48d01447dd0e56edd0abe0be424aa5adf0c30d52e74b66e75d45ea84e3cf3d3
sha512: 175b37c8795a1754ab531c38104797d5a0b9aeeffd48984fc2e363928caf98991dd000f03ff7091406b6cfd6689ce74cb92f156702c3dc181b93668d587b88c2
ssdeep: 98304:zfN7jTzgteJUvp9wgluxdTgLlDTEGtsM/a+MthGpQ7ttBY+ylTlB/rKWO81a1:h7HsteJCp2TgyxfthGS72+07cSm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1074633E282000D33CA756BFE6D83C2D4F9DC2D82ADDD824C1EDF69A9C59998D47A4743
sha3_384: e34252c9b5bbfac90e5a9fe6221ee6dff9cb2fd078532b3856767b229e32278bf2875a670289ccfdd57f5d5af7defd9e
ep_bytes: e84b0100005389e3538b73088b7b10fc
timestamp: 2023-08-01 20:52:01

Version Info:

0: [No Data]

Zusy.485756 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.485756
FireEyeGeneric.mg.1443250bff51bfba
SkyhighBehavesLike.Win32.Generic.tc
ALYacGen:Variant.Zusy.485756
MalwarebytesGeneric.Malware/Suspicious
VIPREGen:Variant.Zusy.485756
SangforTrojan.Win32.Save.a
BitDefenderGen:Variant.Zusy.485756
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36792.@NW@aiN8HVg
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.Themida.CM suspicious
APEXMalicious
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingTrojan.Generic@AI.100 (RDML:v1rl0KLWWnlONZdrUuCQag)
EmsisoftGen:Variant.Zusy.485756 (B)
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
IkarusPUA.Themida
GDataGen:Variant.Zusy.485756
GoogleDetected
VaristW32/Cerbu.BT.gen!Eldorado
Antiy-AVLGrayWare/Win32.Wacapew
ArcabitTrojan.Zusy.D7697C
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.R535424
McAfeeArtemis!1443250BFF51
MAXmalware (ai score=82)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002H09H223
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Cerbu.156416!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.282720
AvastWin32:Evo-gen [Trj]

How to remove Zusy.485756?

Zusy.485756 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment