Malware

Zusy.486729 (B) malicious file

Malware Removal

The Zusy.486729 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.486729 (B) virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Zusy.486729 (B)?


File Info:

name: 3BAFF6565A3F1293D7E5.mlw
path: /opt/CAPEv2/storage/binaries/2034341c599eebf3b3f88d643e10ca0e96ad3670d6c0d8910f79fa2bc2b5fd3c
crc32: 54096840
md5: 3baff6565a3f1293d7e5b80e21348115
sha1: 84e275eb7c5d4f62aa46af51ec42b21c5389bb8a
sha256: 2034341c599eebf3b3f88d643e10ca0e96ad3670d6c0d8910f79fa2bc2b5fd3c
sha512: 9f152a56fcdcc04863823f18d701698d49b5dd33616cff6d13f902ecbab688e8aa07f8a2711ee7c8e5d1e122d6d5cb58b7089bb908bcfc22dc2cd6fa94f7886c
ssdeep: 384:ktqjHpWuZPbvyiUFLlklWx2RsTdUIH4OMLPmJoSSPc:ktqpZPbf2pklWxcY6IH4OML+WSI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E3238DCB019A7A9FC9E9017131A285CF5AF7DFF40179C93B76EC857B5EE21748229280
sha3_384: e98d1720e5d541608480d5dd3dbab53f6ea3cb2c74e96ab502831283cd4de02975761b63a167cd4d0cc11a5613906911
ep_bytes: 60be00d04a008dbe0040f5ff5783cdff
timestamp: 2011-04-25 13:57:24

Version Info:

0: [No Data]

Zusy.486729 (B) also known as:

BkavW32.AIDetectMalware
LionicVirus.Win32.Sality.lRLu
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Zusy.486729
ClamAVWin.Malware.Zusy-9956834-0
FireEyeGeneric.mg.3baff6565a3f1293
SkyhighBehavesLike.Win32.RealProtect.pz
Cylanceunsafe
ZillyaTrojan.GenericML.Win32.438
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaVirus:Win32/Sality.4a9d1f98
K7GWRiskware ( 00584baa1 )
K7AntiVirusRiskware ( 00584baa1 )
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
KasperskyUDS:Trojan.Win32.GenericML.xnet
BitDefenderGen:Variant.Zusy.486729
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
AvastSf:ShellCode-GH [Trj]
EmsisoftGen:Variant.Zusy.486729 (B)
F-SecureTrojan.TR/Crypt.ULPM.Gen
VIPREGen:Variant.Zusy.486729
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan.Crypt
GDataGen:Variant.Zusy.486729
JiangminTrojan.Multi.jtq
GoogleDetected
AviraTR/Crypt.ULPM.Gen
MAXmalware (ai score=80)
Kingsoftmalware.kb.b.995
ArcabitTrojan.Zusy.D76D49
ZoneAlarmUDS:Trojan.Win32.GenericML.xnet
MicrosoftVirus:Win32/Sality.gen!AT
VaristW32/S-92accea0!Eldorado
AhnLab-V3Trojan/Win.ShellCode.R493610
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36744.cmW@aqat84m
ALYacGen:Variant.Zusy.486729
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingVirus.Sality!8.35A (CLOUD)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.82199810.susgen
FortinetW32/ULPM.16C0!tr
AVGSf:ShellCode-GH [Trj]
Cybereasonmalicious.b7c5d4
DeepInstinctMALICIOUS

How to remove Zusy.486729 (B)?

Zusy.486729 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment