Malware

Zusy.486869 (B) (file analysis)

Malware Removal

The Zusy.486869 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.486869 (B) virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.486869 (B)?


File Info:

name: 419F2C0D29192121AB9C.mlw
path: /opt/CAPEv2/storage/binaries/d5345e9bc4f6cce7c64732bd53fe1380363dd98be4b7771d69761fcfce672ba9
crc32: 7D96FF53
md5: 419f2c0d29192121ab9cb13426810725
sha1: 128ed63b36dd8c5f62ac48aa52296df22055a12f
sha256: d5345e9bc4f6cce7c64732bd53fe1380363dd98be4b7771d69761fcfce672ba9
sha512: accb694926b5481b4bb0967669d179e58dbcf6a7f0fc53ab064124e0c21d623aeb7d83ea7629663468f7a10545b5c2a49ba7b39c3c352ce8d3f07bf2f202ec37
ssdeep: 49152:NtnrcWeTueEdOVsYs8dFYvanGVhr726iYoSazY:HrxeTueEdOV6CFYv4u7SYoSazY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A0A5F221B39680FAD2BA497204567F37DD399E461A18CF83A360FD6E6D33240D63716E
sha3_384: cc005c985fda792a3c4b283ff2660b3e3e0607012bf96514a6eb36d84bcc69407faebdba119f792ad525e987be0499c8
ep_bytes: 558bec6aff68389c5b0068e4d4460064
timestamp: 2012-05-11 12:48:25

Version Info:

FileVersion: 1.1.1.1
FileDescription: QQ804584418(玩世)
ProductName: 玩世辅助_WPE【1.1】
ProductVersion: 1.1.1.1
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Zusy.486869 (B) also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.486869
FireEyeGeneric.mg.419f2c0d29192121
ALYacGen:Variant.Zusy.486869
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Zusy.486869
K7AntiVirusTrojan ( 005246d51 )
BitDefenderGen:Variant.Zusy.486869
K7GWPassword-Stealer ( 004a98b61 )
Cybereasonmalicious.b36dd8
ArcabitTrojan.Zusy.D76DD5
CyrenW32/Trojan.IRG.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Cloud-9975987-0
EmsisoftGen:Variant.Zusy.486869 (B)
F-SecureTrojan:W32/DelfInject.R
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosGeneric ML PUA (PUA)
IkarusTrojan.Crypt
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.FlyStudio.a
Kingsoftmalware.kb.a.1000
XcitiumWorm.Win32.Dropper.RA@1qraug
GDataWin32.Trojan.PSE.1NHSFG6
GoogleDetected
DeepInstinctMALICIOUS
VBA32BScope.Trojan.Tonmye
Cylanceunsafe
SentinelOneStatic AI – Malicious PE
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.PHP!tr
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Zusy.486869 (B)?

Zusy.486869 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment