Malware

Zusy.488124 information

Malware Removal

The Zusy.488124 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.488124 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.488124?


File Info:

name: 6BD2029FDA0DC892632F.mlw
path: /opt/CAPEv2/storage/binaries/4509fe562f6b19f3b74be91268eae18ee3990a1ea3a680a790de4b8726b1253c
crc32: A54D9B44
md5: 6bd2029fda0dc892632fdfd741b584b2
sha1: 82e4432f610598a324ca3a2c36e8c5f105ff8981
sha256: 4509fe562f6b19f3b74be91268eae18ee3990a1ea3a680a790de4b8726b1253c
sha512: 95602c057d139c225dc185c7458960303d2e5e4123a9017159ccccd46977da3de050eb81f14d5332aabac4a31984dd58c3ce9017d2ca7d505fc4bd4521d9dae4
ssdeep: 6144:h6LKgZ9lwqPpRj4VstrcEjOvEK+B6scEEsp6dIi+y5MyiT:hTqPpoADIEKPs5MdP+y5My
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T10974AD00F7D58514F0B26F329AB452540A3BBAA96B30C1CF917B815D6BA35C98DF9B33
sha3_384: 4d9ae7bed95f992c04ac4d5bad64523697bd0b7d19dbca91b2b234dbfc0986af5fd193492bab2e5bf24b91e162d45c9f
ep_bytes: e8a9050000e96ffeffffccccccccccc3
timestamp: 2019-05-06 14:43:24

Version Info:

Platform: NT
LegalTrademarks: Microsoft SQL Server is a registered trademark of Microsoft Corporation.
Comments: SQL
GoldenBits: True
CompanyName: Microsoft Corporation
FileDescription: SQL External minidumper
FileVersion: 2019.0150.1500.158 ((BI_Main).190506-1918)
InternalName: SqlDumper
LegalCopyright: Microsoft. All rights reserved.
OriginalFilename: SqlDumper.exe
ProductName: Microsoft SQL Server
ProductVersion: 15.0.1500.158
Translation: 0x0409 0x04b0

Zusy.488124 also known as:

BkavW32.AIDetectMalware
DrWebWin32.Beetle.2
MicroWorld-eScanGen:Variant.Zusy.488124
MalwarebytesFloxif.Virus.FileInfector.DDS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005ab4bf1 )
K7GWTrojan ( 005ab4bf1 )
Cybereasonmalicious.f61059
CyrenW32/Sinowal.AW.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Patched.NKM
APEXMalicious
KasperskyVHO:Trojan.Win32.Convagent.gen
BitDefenderGen:Variant.Zusy.488124
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AvastWin32:TrojanX-gen [Trj]
RisingTrojan.Generic@AI.100 (RDML:7FxI0cJDRi4pEhTIyAHrGg)
EmsisoftGen:Variant.Zusy.488124 (B)
VIPREGen:Variant.Zusy.488124
McAfee-GW-EditionBehavesLike.Win32.Expiro.fc
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.6bd2029fda0dc892
GDataGen:Variant.Zusy.488124
JiangminTrojan.Injuke.skr
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Sabsik
ArcabitTrojan.Zusy.D772BC
ZoneAlarmVHO:Trojan.Win32.Convagent.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R603704
VBA32BScope.TrojanDownloader.Emotet
ALYacGen:Variant.Zusy.488124
PandaTrj/Genetic.gen
TencentMalware.Win32.Gencirc.10bf1f8e
IkarusTrojan.Win32.Krypt
FortinetW32/Patched.IP!tr
AVGWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Zusy.488124?

Zusy.488124 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment