Malware

Zusy.439473 (B) (file analysis)

Malware Removal

The Zusy.439473 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.439473 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Arabic (Algeria)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Zusy.439473 (B)?


File Info:

name: 627C6AE541C2C9982E99.mlw
path: /opt/CAPEv2/storage/binaries/b2b1a840a630a545a76b12a07c720493c19b7e0ed0af80cb59e1e2b48a1c7ccf
crc32: F99BA5E6
md5: 627c6ae541c2c9982e9916baa1f4f494
sha1: 86fdc3da9af091857e05ac7fa7539b43e8f5e9b4
sha256: b2b1a840a630a545a76b12a07c720493c19b7e0ed0af80cb59e1e2b48a1c7ccf
sha512: a0f7c153858bea7cdc0abe0e5f88b8c99b9ff66cfa5bc93631eb6b7bcc755f8d94f96286c6a6694963dcef7680bc5570c5cd1fd52a64548b361b7d6f50098555
ssdeep: 98304:3Uj4pKO+6PbFmS3VjVEOeTtJaAbLECnrZXJT7x:3jbFmS3VjVEOeTtJHbdnrz7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12536DF2AB70981B7DA7177F199AB65DE9430DC30D06940F8EE830B48E516EB743BA347
sha3_384: 6f2352c39899d0ce017b58c60fb64193aadab55389815be8d8096fef85315b5a5192675978ff3db1e1c9d65b2855ff2c
ep_bytes: 558bec83c4f0b890034500e89055fbff
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: Steganos Software GmbH
FileDescription: Steganos Shredder
FileVersion: 17.0.2.11443
InternalName: ShredderLow.exe
OriginalFilename: ShredderLow.exe
LegalCopyright: Copyright (c) 2013 Steganos Software GmbH
LegalTrademarks: Steganos Safe 17 is a trademark of Steganos Software GmbH
ProductName: Steganos Safe 17
ProductVersion: 17.0.2.11443
Comments: Steganos Safe 17
Translation: 0x0409 0x04e4

Zusy.439473 (B) also known as:

Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Zusy.439473
FireEyeGeneric.mg.627c6ae541c2c998
CylanceUnsafe
VIPREGen:Variant.Zusy.439473
SangforTrojan.Win32.Save.a
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 100)
BitDefenderGen:Variant.Zusy.439473
Ad-AwareGen:Variant.Zusy.439473
SophosTroj/Delf-HOV
EmsisoftGen:Variant.Zusy.439473 (B)
IkarusTrojan-Dropper.Win32.Dapato
GDataGen:Variant.Zusy.439473
MAXmalware (ai score=88)
ArcabitTrojan.Zusy.D6B4B1
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3PUP/Win32.DealPly.C2737829
VBA32BScope.Trojan.Sabsik.FL
ALYacGen:Variant.Zusy.439473
MalwarebytesMalware.AI.4278002693
APEXMalicious
RisingTrojan.Win32.Agent.cje (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FSCS!tr

How to remove Zusy.439473 (B)?

Zusy.439473 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment