Malware

Zusy.434473 (file analysis)

Malware Removal

The Zusy.434473 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.434473 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Spanish (Mexican)
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Zusy.434473?


File Info:

name: 593D4E901382CAB47DA7.mlw
path: /opt/CAPEv2/storage/binaries/9386d3fb71df60fff506f567b31810d86212f9be10849f23e9e31beda3b5f60a
crc32: 8F45E428
md5: 593d4e901382cab47da740e8bce44cb8
sha1: 4da691a228ea1000fa0938cdeec13e4cc988c1f9
sha256: 9386d3fb71df60fff506f567b31810d86212f9be10849f23e9e31beda3b5f60a
sha512: 11a82a617fe7f486fc853b591fafa62e0746c840b75f4dd8a6a4bf751d875057835b9716eb0457c7a0886ce7bf9d55c26ea74873565097189180835443461cb7
ssdeep: 49152:Y2giSqWhCYFQB9sYC4a5wApcrBhhNZyjjbHSAHtCnLK2kfBvCMI:YR+OQFLTkfMMI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T149855B64C5B44443F4A830351249BA3F78162BB27B7C4D32BBE47B3116BE24AD92976F
sha3_384: 8920ef3225b7216b0f185998242d583b65ee05099870f22312360330b1860815508315a2c0b7854959bb6cf6349aea93
ep_bytes: 558bec6aff68a0d94a0068008c4a0064
timestamp: 2015-05-15 12:12:14

Version Info:

Comments:
CompanyName: Satinfo SL.
FileDescription: Utilidad
FileVersion: 2, 14, 4, 14
InternalName: Elis
LegalCopyright: Copyright (C) 2015
LegalTrademarks:
OriginalFilename: Elis.EXE
PrivateBuild:
ProductName: Aplicación Elis
ProductVersion: 2, 14, 4, 14
SpecialBuild:
Translation: 0x0c0a 0x04b0

Zusy.434473 also known as:

tehtrisGeneric.Malware
DrWebTrojan.Siggen6.35999
MicroWorld-eScanGen:Variant.Zusy.434473
FireEyeGeneric.mg.593d4e901382cab4
ALYacGen:Variant.Zusy.434473
CylanceUnsafe
VIPREGen:Variant.Zusy.434473
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 004bcce41 )
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.01382c
ArcabitTrojan.Zusy.D6A129
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
Kasperskynot-a-virus:WebToolbar.Win32.Estapa.vg
BitDefenderGen:Variant.Zusy.434473
AvastWin32:Malware-gen
RisingTrojan.Agent!1.6853 (CLASSIC)
Ad-AwareGen:Variant.Zusy.434473
EmsisoftGen:Variant.Zusy.434473 (B)
ComodoTrojWare.Win32.TrojanDownloader.IstBar.~L@f815z
ZillyaAdware.Estapa.Win32.330
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
IkarusTrojan-Downloader.Win32.IstBar
JiangminHeur:TrojanDownloader.Agent
WebrootW32.Downloader.Gen
GoogleDetected
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3C17
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Zusy.434473
CynetMalicious (score: 100)
McAfeeGenericRXAA-FA!593D4E901382
MAXmalware (ai score=89)
VBA32BScope.Trojan.DiskWriter
MalwarebytesMalware.Heuristic.1003
YandexTrojan.GenAsa!F4O8qdW+2fg
SentinelOneStatic AI – Malicious PE
AVGWin32:Malware-gen

How to remove Zusy.434473?

Zusy.434473 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment