Malware

About “Zusy.473197” infection

Malware Removal

The Zusy.473197 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.473197 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Zusy.473197?


File Info:

name: 1EE151E540FB8A6D4935.mlw
path: /opt/CAPEv2/storage/binaries/989a523988a932ceeb8bdf419d97bdca303da7f23ddcd4d14539e607d03020cb
crc32: 3D0BA8F0
md5: 1ee151e540fb8a6d493508cc8fc3f01e
sha1: 9e4e5abda0d8bdfa5bbe665090d1439b18444d3b
sha256: 989a523988a932ceeb8bdf419d97bdca303da7f23ddcd4d14539e607d03020cb
sha512: 36c201fc02ab6ffd2ef2ae79a00f0c482768209e0caa6ef4516a0489d782f781c688967f47ea1dbc7f1a675d0e3119108c867fdeba31418c6239b4b312db4466
ssdeep: 6144:gV0g8uqI4jwkREvA7MZi/AaOU6uAlTxGj0CeJQJQmZ:/gjr4PYaOU6xTxTQJQmZ
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12454AE176F40D53AC01FDC7528AA8B79CE65BD351B6452C37BC2452A9A383F1A6BC2CC
sha3_384: 653e4a35fe598c1e14e4519a396fc7019e7cc237f2d50b5abe5f97597ce579181eec23736b724eb3ffdc8102a8859cdd
ep_bytes: e82a680000e9a4feffff6a0c68501f42
timestamp: 2023-06-18 07:33:56

Version Info:

Comments: This is a legitimate application.
CompanyName: Georgia Capital
FileDescription: Georgia Capital Product
FileVersion: 653
InternalName: xMWNeGXRe7mr
LegalCopyright: © Georgia Capital All rights reserved.
LegalTrademarks: © Georgia Capital Trademarks
OriginalFilename: gJjqY0Ce.exe
ProductName: dEKa80oRcW
ProductVersion: 653
Translation: 0x0407 0x04b0

Zusy.473197 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealer.12!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.473197
FireEyeGeneric.mg.1ee151e540fb8a6d
CAT-QuickHealTrojan.GenericPMF.S30319961
SkyhighBehavesLike.Win32.Generic.dh
ALYacGen:Variant.Zusy.473197
Cylanceunsafe
VIPREGen:Variant.Zusy.473197
SangforInfostealer.Win32.Kryptik.Vm3f
K7AntiVirusTrojan ( 005a75591 )
AlibabaTrojanSpy:Win32/Stealer.d7a85e89
K7GWTrojan ( 005a75591 )
BitDefenderThetaGen:NN.ZexaF.36804.su2@a4KM0Zbi
VirITTrojan.Win32.Genus.RKD
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.GKWT
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Pwsx-10004807-0
KasperskyHEUR:Trojan-Spy.Win32.Stealer.pef
BitDefenderGen:Variant.Zusy.473197
NANO-AntivirusTrojan.Win32.Stealer.jxedcs
AvastWin32:TrojanX-gen [Trj]
TencentTrojan-DL.Win32.Deyma.kd
EmsisoftGen:Variant.Zusy.473197 (B)
F-SecureHeuristic.HEUR/AGEN.1364950
DrWebTrojan.PWS.Stealer.35843
ZillyaTrojan.Stealer.Win32.113335
Trapminemalicious.high.ml.score
SophosTroj/Krypt-ZM
IkarusTrojan.Win32.Redline
GDataWin32.Trojan.PSE.164AIIY
JiangminTrojanSpy.Stealer.aioz
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1364950
VaristW32/Stealer.EA.gen!Eldorado
Antiy-AVLTrojan/Win32.GenKryptik
KingsoftWin32.Troj.Unknown.a
ArcabitTrojan.Zusy.D7386D
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.pef
MicrosoftTrojan:Win32/RedLineStealer.EN!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C5443150
McAfeeArtemis!1EE151E540FB
MAXmalware (ai score=83)
VBA32BScope.TrojanPSW.RedLine
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!8.8 (TFE:5:u5ZXrIA6OcE)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.HSYN!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudTrojan[spy]:Win/RedLineStealer.EN!MTB

How to remove Zusy.473197?

Zusy.473197 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment