Malware

Zusy.475213 information

Malware Removal

The Zusy.475213 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.475213 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.475213?


File Info:

name: F2308E79C4C7E141D9B2.mlw
path: /opt/CAPEv2/storage/binaries/0f95d9972c171610a0c798c507cb32b39f21a0cfa918758a7b2cfadaffadad73
crc32: 6D523D79
md5: f2308e79c4c7e141d9b25fb6defd2f6f
sha1: f22da4b74efdcfb3f5d65cb6532d38c5951a8fbc
sha256: 0f95d9972c171610a0c798c507cb32b39f21a0cfa918758a7b2cfadaffadad73
sha512: f5203c207b116e4b466cfa33ef513972bd7b6d4cedc464c4f20e133b8f2917bf2890e7f44651581762eb0fa73c218a8a092cd1ec5fa03316d134c9e801b3bfbd
ssdeep: 12288:e+ZY+iYmbUQUyThcHgATdyl+QPmoLN3d:eEYJYJH/H7K+QPmO3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T188A49D037601D0E6D42137BB9097073D7DB8475939B8D823A7E49E66BCB0472EB2FA49
sha3_384: c81d3c299068302934d08bc01d5c6c8c462d3ada9f295c825f4513bc2c1ff96e9bbcfaba93bb7c8441a827d1976732ce
ep_bytes: e8cb030200e80301020033c0c3909090
timestamp: 2023-07-12 18:29:24

Version Info:

0: [No Data]

Zusy.475213 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Zusy.475213
ClamAVWin.Dropper.Tiggre-9845940-0
FireEyeGeneric.mg.f2308e79c4c7e141
ALYacGen:Variant.Zusy.475213
MalwarebytesGeneric.Malware.AI.DDS
SangforTrojan.Win32.Save.BlackMoon
AlibabaBackdoor:Win32/Poison.5919fb35
Cybereasonmalicious.74efdc
CyrenW32/Injector.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.BlackMoon.A suspicious
APEXMalicious
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Poison.klth
BitDefenderGen:Variant.Zusy.475213
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Backdoor.Poison.Edhl
EmsisoftGen:Variant.Zusy.475213 (B)
DrWebTrojan.Inject4.59092
VIPREGen:Variant.Zusy.475213
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
Trapminemalicious.high.ml.score
SophosMal/FakeAV-PH
SentinelOneStatic AI – Malicious PE
Antiy-AVLTrojan/Win32.Blamon.a
ArcabitTrojan.Zusy.D7404D
ZoneAlarmBackdoor.Win32.Poison.klth
GDataWin32.Trojan.PSE.1DPEYYJ
GoogleDetected
AhnLab-V3Trojan/Win.Generic.C5451877
Acronissuspicious
McAfeeGenericRXGT-WP!F2308E79C4C7
MAXmalware (ai score=87)
VBA32BScope.DDoS.Npf
Cylanceunsafe
RisingTrojan.Generic@AI.94 (RDML:W+ub7T3+tcGHXATBmhC2RQ)
IkarusAdWare.Win32.BlackMoon
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.WP!tr
BitDefenderThetaGen:NN.ZexaF.36318.CqW@a8X0cQn
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Zusy.475213?

Zusy.475213 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment