Malware

Should I remove “Zusy.472379 (B)”?

Malware Removal

The Zusy.472379 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.472379 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the MetaStealer malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Zusy.472379 (B)?


File Info:

name: 426C495262F37D8D0482.mlw
path: /opt/CAPEv2/storage/binaries/2d873fb5e5df1ecafccb3eeaa6dc1835676d7f43938ff37a623285a086d6208d
crc32: 49E30B6A
md5: 426c495262f37d8d04821cb0ff469221
sha1: 3140d43ae2005adf8f8b67ca4fc3442cd5d9b661
sha256: 2d873fb5e5df1ecafccb3eeaa6dc1835676d7f43938ff37a623285a086d6208d
sha512: 1413bef727d485e48feb79914b9846061cf0b70d2f221cc13823aad81ebb6621b2f371162208c1c06865b7789dfed9e9a48678af36a71d39f30681eb93d7b463
ssdeep: 6144:49JEO6VqTLI5gWWIoX3VWXPzRUITugwCZBq:iJT6gTLyPzRUIE
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12C544CC0991CD751E2838472F87742136A0CE86A7984D7EF2F8AA17CB5B6AD1CC54ED3
sha3_384: 8931b5fe7945fd5c8396b10d7194cada11852321f5103a17090cb06f4f17749f92e97da9570746518ee56e22250073eb
ep_bytes: e8173c0000e9a4feffff3b0d2c134400
timestamp: 2023-06-13 08:34:32

Version Info:

Comments: Esta es una aplicación legítima.
CompanyName: Telefónica
FileDescription: Telefónica Produit
FileVersion: 572
InternalName: AplicacionInterna
LegalCopyright: Derechos de autor © Telefónica Todos los derechos reservados.
LegalTrademarks: Marcas registradas © Telefónica
OriginalFilename: app.exe
ProductName: Aplicacion
ProductVersion: 572
Translation: 0x0407 0x04b0

Zusy.472379 (B) also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealer.12!c
MicroWorld-eScanGen:Variant.Zusy.472379
FireEyeGeneric.mg.426c495262f37d8d
CAT-QuickHealTrojan.GenericPMF.S30244154
SkyhighGenericRXWE-EQ!426C495262F3
ALYacGen:Variant.Zusy.472379
Cylanceunsafe
ZillyaTrojan.Stealer.Win32.104262
SangforTrojan.Win32.Save.a
AlibabaTrojanSpy:Win32/Stealer.d4c8ef86
K7GWTrojan ( 005a70711 )
K7AntiVirusTrojan ( 005a70711 )
VirITTrojan.Win32.GenusT.DNAA
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HTUE
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0DBD24
AvastWin32:CrypterX-gen [Trj]
ClamAVRevoked.CRT.AnyDesk_Compromise-10020555-0
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Variant.Zusy.472379
NANO-AntivirusTrojan.Win32.Stealer.jwwlkj
TencentTrojan.Win32.Kryptik.16000698
EmsisoftGen:Variant.Zusy.472379 (B)
F-SecureHeuristic.HEUR/AGEN.1364927
DrWebTrojan.PWS.Stealer.36123
VIPREGen:Variant.Zusy.472379
TrendMicroTROJ_GEN.R002C0DBD24
Trapminemalicious.high.ml.score
SophosMal/Generic-S
Paloaltogeneric.ml
MAXmalware (ai score=100)
JiangminTrojan.PSW.Reline.aep
WebrootW32.Adware.Gen
GoogleDetected
AviraHEUR/AGEN.1364927
VaristW32/Kryptik.JZU.gen!Eldorado
Antiy-AVLTrojan/Win32.Kryptik
KingsoftWin32.Trojan-Spy.Stealer.gen
MicrosoftTrojan:Win32/Redline!ic
XcitiumMalware@#298lpkyqtec1i
ArcabitTrojan.Zusy.D7353B
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
GDataWin32.Trojan.PSE.5KLFVB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R586713
McAfeeGenericRXWE-EQ!426C495262F3
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Chgt.AD
RisingTrojan.Kryptik!1.E83E (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.HTUE!tr
AVGWin32:CrypterX-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudMalware

How to remove Zusy.472379 (B)?

Zusy.472379 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment