Malware

About “Zusy.496804” infection

Malware Removal

The Zusy.496804 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.496804 virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempted to write directly to a physical drive

How to determine Zusy.496804?


File Info:

name: 45C2F73E8A02C1816EC7.mlw
path: /opt/CAPEv2/storage/binaries/a10dce4c8a1b941d65faa9339a026ab6d77152c66f164d06d5debe7136a844c3
crc32: 05ADF703
md5: 45c2f73e8a02c1816ec7261c1aa257f3
sha1: 323726036ac094891ff35f21ee77f83a3182c994
sha256: a10dce4c8a1b941d65faa9339a026ab6d77152c66f164d06d5debe7136a844c3
sha512: a3a9a9d62136224c16f692d067b0acb012af30021998cd4b36c84da6618f60fa64ceeb5ec3755bd7efddca35359f7c6c13e9e8fa32588b85743b798078b968bb
ssdeep: 24576:hJ+tJm/lgewKSzFaSnRxuSTdf2FfWl8KuqGavkg3NyNIbbbIoIBAUZLYh:hAslgevSRxz9+s8KuqGaX0ToIBAUZLY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AE65C002F3C2C5B3E5275530497AAB36D666DD194B05CA83B3A5FE9D0D333E0A47623A
sha3_384: 4287f0f2430ce085ac6d57a8cca668c1e30cb1e1d8bf905ffe04e586ff944d5ca6f020e3bbcbe977ff0ec86302d7f61b
ep_bytes: 558bec6aff688858550068205b460064
timestamp: 2012-06-09 05:34:35

Version Info:

0: [No Data]

Zusy.496804 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lwTx
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.496804
FireEyeGeneric.mg.45c2f73e8a02c181
SkyhighBehavesLike.Win32.Generic.tc
McAfeeArtemis!45C2F73E8A02
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Zusy.496804
SangforTrojan.Win32.Agent.Vqjj
K7AntiVirusTrojan ( 005246d51 )
BitDefenderGen:Variant.Zusy.496804
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.36ac09
BitDefenderThetaGen:NN.ZexaF.36792.ErW@aOvg6Wlb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
RisingTrojan.Generic@AI.99 (RDML:ESiDi4++SDmjYlX5zMVq9w)
TACHYONTrojan/W32.Agent.1540096.DX
SophosGeneric Reputation PUA (PUA)
F-SecureTrojan:W32/DelfInject.R
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Zusy.496804 (B)
VaristW32/S-9a0e6078!Eldorado
Antiy-AVLTrojan/Win32.FlyStudio.a
Kingsoftmalware.kb.a.994
MicrosoftTrojan:Win32/Wacatac.B!ml
XcitiumWorm.Win32.Dropper.RA@1qraug
ArcabitTrojan.Zusy.D794A4
GDataWin32.Trojan.PSE.192BHS8
GoogleDetected
ALYacGen:Variant.Zusy.496804
MAXmalware (ai score=89)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H0CJC23
SentinelOneStatic AI – Malicious PE
FortinetRiskware/Application
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Zusy.496804?

Zusy.496804 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment