Malware

About “Zusy.487462” infection

Malware Removal

The Zusy.487462 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.487462 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Creates a copy of itself
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.487462?


File Info:

name: 5343D819DC381241EB5B.mlw
path: /opt/CAPEv2/storage/binaries/17d39b3c16dcc88054885c08a8c334198dada6dcccdcfaa76b8f1f8b4f1386eb
crc32: 88A240C8
md5: 5343d819dc381241eb5bcb1ede79ecce
sha1: 931a62488919dfc20c84df55daf6e6c4463f673b
sha256: 17d39b3c16dcc88054885c08a8c334198dada6dcccdcfaa76b8f1f8b4f1386eb
sha512: d01a85862eefcd5300a4f8b9254759181889b1fc608560c41b1ff9f6ffe9fdf31230445cdfb23248a893f35c8113d2cad0a4e27c053cadaa62be754a3a7e2058
ssdeep: 393216:klnarD9IACofelmP7+7sv06qVyCZ5sDhanYK:onaNIACofymPOMjDYYK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13CE63396249291DBD98B4275CC6ACEB626266D20EEF050DB0BC37C0737FF11461B6BE1
sha3_384: ea5a344da798231349be60af38dda0c93e14f853291242f8b8b74a42ec64485aac8fd87402838c8b2f67339449987a93
ep_bytes: b830f29c005064ff3500000000648925
timestamp: 2023-05-26 13:26:29

Version Info:

0: [No Data]

Zusy.487462 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.487462
FireEyeGeneric.mg.5343d819dc381241
McAfeeArtemis!5343D819DC38
MalwarebytesMalware.Heuristic.1001
VIPREGen:Variant.Zusy.487462
SangforTrojan.Win32.Save.a
K7AntiVirusAdware ( 005848221 )
K7GWAdware ( 005848221 )
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderThetaGen:NN.ZexaF.36662.@lZfa4aycvb
CyrenW32/FlyStudio.BB.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Zusy.487462
EmsisoftGen:Variant.Zusy.487462 (B)
F-SecureHeuristic.HEUR/AGEN.1338690
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.high.ml.score
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.1M5WJ7V
AviraHEUR/AGEN.1338690
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.FlyStudio.a
ArcabitTrojan.Zusy.D77026
MicrosoftProgram:Win32/Wacapew.C!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R568032
ALYacGen:Variant.Zusy.487462
DeepInstinctMALICIOUS
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H09IC23
FortinetRiskware/Application
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.88919d
AvastWin32:MalwareX-gen [Trj]

How to remove Zusy.487462?

Zusy.487462 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment