Malware

Zusy.477833 removal

Malware Removal

The Zusy.477833 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.477833 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Zusy.477833?


File Info:

name: 2EA3ABDFB9EDD25AE42A.mlw
path: /opt/CAPEv2/storage/binaries/7fa3c5834b84ea8477922db1a9c7ff3538fa665dd3b68517f0d2f355bbf0bede
crc32: CC3FBD4E
md5: 2ea3abdfb9edd25ae42a5c625268a200
sha1: e4da39ebffc5b0e9ef4498c523842e081ccb0a0d
sha256: 7fa3c5834b84ea8477922db1a9c7ff3538fa665dd3b68517f0d2f355bbf0bede
sha512: 91c2be438dc95a5d8d09e0fd9d96e9edbb2d72c88b7e55cb404c8dc6e071140a1872679d25a816ebab6900d1ff824d3bcb939d8dd50fdcb336889184bc566301
ssdeep: 6144:ImLHLdb3DaEX3pENyK4q/AG14SuBxw7yvRF95DQ4sXlrwaDlLKTbKV5vmtLquPqE:hLpT+U3y4q4GuSSxtv95bnap9VBAq7Y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B135E087F26881FDD17F4535DC69821D85237CF0AFB882847ECA374EAB38251892675B
sha3_384: 9b94ab68fcf87254a3277580afb77b261d139db6bd84c496c7a0cfa78409e2ec94b04c6cf7c25c7ab084e805c637f1c6
ep_bytes: 60be004024018dbe00d0ebff57eb0b90
timestamp: 2019-05-11 14:44:33

Version Info:

FileDescription: BrokerLib
OriginalFilename: TokenBrokerCookies
CompanyName: WpcMon
FileVersion: 976.641.47.426
LegalCopyright: relog
ProductName: reg
ProductVersion: 909.509.224.548
Translation: 0x0409 0x04b0

Zusy.477833 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Zusy.477833
FireEyeGeneric.mg.2ea3abdfb9edd25a
McAfeeArtemis!2EA3ABDFB9ED
MalwarebytesGeneric.Malware.AI.DDS
ZillyaBackdoor.Autoit.Win32.4
SangforTrojan.Win32.Save.a
Cybereasonmalicious.fb9edd
BitDefenderThetaGen:NN.ZexaF.36350.gn0@auSwj6oi
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
TrendMicro-HouseCallTrojan.AutoIt.CRYPTINJECT.SMA
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.AutoIt.ed
BitDefenderGen:Variant.Zusy.477833
AvastAutoIt:Injector-JF [Trj]
SophosGeneric ML PUA (PUA)
F-SecureHeuristic.HEUR/AGEN.1321257
DrWebTrojan.AutoIt.421
VIPREGen:Variant.Zusy.477833
TrendMicroTrojan.AutoIt.CRYPTINJECT.SMA
McAfee-GW-EditionBehavesLike.Win32.Generic.tt
EmsisoftGen:Variant.Zusy.477833 (B)
IkarusTrojan.Crypt
GDataGen:Variant.Zusy.477833
JiangminBackdoor.AutoIt.gq
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1321257
MAXmalware (ai score=88)
Antiy-AVLGrayWare/Autoit.ShellCode.a
ArcabitTrojan.Zusy.D74A89
ZoneAlarmBackdoor.Win32.AutoIt.ed
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Malware/Win32.Generic.C3239128
Acronissuspicious
Cylanceunsafe
APEXMalicious
RisingPUF.Pack-AutoIt!1.B8E7 (CLASSIC)
SentinelOneStatic AI – Suspicious PE
FortinetW32/ULPM.16C0!tr
AVGAutoIt:Injector-JF [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Zusy.477833?

Zusy.477833 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment