Malware

Zusy.497586 (file analysis)

Malware Removal

The Zusy.497586 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.497586 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.497586?


File Info:

name: 7CC10238F5B13E17F5A6.mlw
path: /opt/CAPEv2/storage/binaries/1dd2a2a7c520515d9d890eb5a1e77104bf5d507b232b7e45817553a76195c6aa
crc32: DEA86BB4
md5: 7cc10238f5b13e17f5a63ee8e2e3c466
sha1: 9c762ebdd84cfbb731ae79657a60a83fc9a935fb
sha256: 1dd2a2a7c520515d9d890eb5a1e77104bf5d507b232b7e45817553a76195c6aa
sha512: 89064b4f7bc47e2eb6b605a1fec6d8768358cd8168248d026e4ceda5704cf177bd71e8559f5a1ea8ec4b3859eed076032d6179b9e2f8733c431e3000cdc70111
ssdeep: 49152:viryQLcXsu78wKYM+s8KuqGaX0ToIBAUZLYV0:q/4u5YfJBAUZLh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T158A5BF02FAC288B3DD53587048772736BA37DE422F15C783A328FE697D33291656A1D9
sha3_384: 5623ca6f9ffc1039f34c5bb9f0eb4a014d43bfc37bb27eaf5182cf71766ceeab50a6d42461e572eefd556fdd6db3eaae
ep_bytes: 558bec6aff68e0d85d0068b40a4d0064
timestamp: 2013-04-06 03:07:19

Version Info:

FileVersion: 1.0.0.0
FileDescription: 淘一族网络应用软件QQ1031261277
ProductName: 淘一族网络应用软件
ProductVersion: 1.0.0.0
CompanyName: 淘一族网络QQ1031261277
LegalCopyright: 承接定制各类网络应用软件,网页POST,游戏辅助,办公软件。QQ1031261277
Comments: 承接定制各类网络应用软件,网页POST,游戏辅助,办公软件。QQ1031261277
Translation: 0x0804 0x04b0

Zusy.497586 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.497586
FireEyeGeneric.mg.7cc10238f5b13e17
SkyhighBehavesLike.Win32.Generic.vh
ALYacGen:Variant.Zusy.497586
Cylanceunsafe
SangforTrojan.Win32.Agent.Vvxz
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.dd84cf
BitDefenderThetaGen:NN.ZexaF.36680.ds0@aq9QO0kb
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
BitDefenderGen:Variant.Zusy.497586
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Variant.Zusy.497586 (B)
VIPREGen:Variant.Zusy.497586
SophosGeneric Reputation PUA (PUA)
SentinelOneStatic AI – Malicious PE
VaristW32/OnlineGames.HG.gen!Eldorado
Antiy-AVLTrojan/Win32.FlyStudio.a
MicrosoftTrojan:Win32/Wacatac.A!ml
XcitiumWorm.Win32.Dropper.RA@1qraug
ArcabitTrojan.Zusy.D797B2
GDataWin32.Trojan.PSE.11SCEUB
GoogleDetected
AhnLab-V3Adware/Win.Generic.C5509298
McAfeeArtemis!7CC10238F5B1
MAXmalware (ai score=83)
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallTROJ_GEN.R002H09KL23
RisingTrojan.Generic@AI.100 (RDML:vMK4jX+34PR5o6e5b26pjw)
IkarusBackdoor.Win32.BlackHole
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/FlyApplication
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Zusy.497586?

Zusy.497586 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment