Malware

Ser.Zusy.4173 (file analysis)

Malware Removal

The Ser.Zusy.4173 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Zusy.4173 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Ser.Zusy.4173?


File Info:

name: 4EC06EE73E553952A16D.mlw
path: /opt/CAPEv2/storage/binaries/7cda71d3178c3e759850bec07b5abf7c116fca57a1064e13849d630bdf80f6a6
crc32: AC5DAD58
md5: 4ec06ee73e553952a16d93a9af686ce9
sha1: 0e41a52b40b0448f7be227f000927b67514e5d25
sha256: 7cda71d3178c3e759850bec07b5abf7c116fca57a1064e13849d630bdf80f6a6
sha512: e8120a029bcbc1e66831f6b7af5fb17addf1c9f769a2f40afb03ae38622271cd2cba2cd9c135b8517e7c99d8d34c5661f42f46e28632d663d454fa3ee8e0365c
ssdeep: 3072:oncOz4H9diPKNODq7CFLuBpaFBzxk7c7awSZohDnjV2S8NmMx3WarRDSAzsUiztO:oMiSwLuBpszxk7USZoDnp23xmg9wUut
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CF84D9157390FB2AD521C6F07A5A83A0A53EED3254B1A807F7D12F2A73B1D5BE121723
sha3_384: 6aebfc06a6100208b4443567433fa4c4ab7c2c562313141af8ff38a6769260720983501b9d233211476475316e2e3936
ep_bytes: 6898444000e8f0ffffff000040000000
timestamp: 2012-01-06 01:53:21

Version Info:

0: [No Data]

Ser.Zusy.4173 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.Heur.PT.wmZ@bSXLS2b
CAT-QuickHealTrojan.Beebone.D
McAfeeVBObfus.eq
Cylanceunsafe
SangforSuspicious.Win32.Save.vb
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.73e553
BitDefenderThetaAI:Packer.7F11538B1E
VirITTrojan.Win32.Zyx.HC
CyrenW32/Vobfus.AI.gen!Eldorado
SymantecW32.Changeup
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Ser.Zusy.4173
NANO-AntivirusTrojan.Win32.Otran.jvquzv
AvastWin32:AutoRun-CMZ [Trj]
RisingWorm.Pronoy!1.9A2F (CLASSIC)
BaiduWin32.Trojan.Inject.n
F-SecureTrojan.TR/Otran.ammy
DrWebWorm.Siggen.10733
VIPREGen:Variant.Ser.Zusy.4173
McAfee-GW-EditionBehavesLike.Win32.VBObfus.ft
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-U
SentinelOneStatic AI – Malicious PE
AviraTR/Otran.ammy
Antiy-AVLWorm/Win32.WBNA.gen
ArcabitTrojan.Ser.Zusy.D104D
ViRobotWorm.Win32.A.WBNA.303104.AAL
ZoneAlarmWorm.Win32.Vobfus.dgbw
GoogleDetected
AhnLab-V3Trojan/Win32.Diple.R93812
Acronissuspicious
ALYacGen:Variant.Ser.Zusy.4173
TACHYONTrojan/W32.VB-Agent.372736.CA
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SMAB
TencentWorm.Win32.Vobfus.kc
YandexTrojan.GenAsa!1iZFKuhiRA4
IkarusTrojan.Win32.Otran
FortinetW32/Diple.EJQE!tr
AVGWin32:AutoRun-CMZ [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ser.Zusy.4173?

Ser.Zusy.4173 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment