Malware

About “Zusy.478194” infection

Malware Removal

The Zusy.478194 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.478194 virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Zusy.478194?


File Info:

name: 7BC382A4271A4B49BC40.mlw
path: /opt/CAPEv2/storage/binaries/63f6bcca91445b6a3f508a207b507db66010b827bfc723b5f7dca2ff84841869
crc32: 22A03FEA
md5: 7bc382a4271a4b49bc40ec5b7289fb12
sha1: 71e2bdc8dd14aa0784768966aa693e74c6c5375a
sha256: 63f6bcca91445b6a3f508a207b507db66010b827bfc723b5f7dca2ff84841869
sha512: 9cd0edbeef1e2b2d053ca2e17e6097cfc9748bc518030f7a1af4a1ee009e8b54a2d033b960deca785b26e2fcb29704dea53c928acb5d46fd298b439cfd7df8b6
ssdeep: 768:fQcPWqpdxEEkcoawoYVUrwHBu8GnTJr/RcajdBsgXQxpM:hrpXkcBwg8mFTRhBsCQxpM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11D133A0867EC433BDB6ECBBDF4F101264370E056B523FB596D8CA9E529633814A527A3
sha3_384: 6ab7561bec42b0af45566274822947b8134b73814e68a48d00cc2410373c5839eecc6155122457db1364a99fb9cafa85
ep_bytes: ff250020400000010203040608080000
timestamp: 2093-05-29 11:07:43

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: CheckVirus
FileVersion: 1.0.0.0
InternalName: CheckVirus.exe
LegalCopyright: Copyright © 2023
LegalTrademarks:
OriginalFilename: CheckVirus.exe
ProductName: CheckVirus
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Zusy.478194 also known as:

MicroWorld-eScanGen:Variant.Zusy.478194
FireEyeGen:Variant.Zusy.478194
ALYacGen:Variant.Zusy.478194
MalwarebytesGeneric.Malware/Suspicious
SangforInfostealer.Msil.Zusy.Vsmu
AlibabaTrojan:MSIL/TyphonSteal.25dc3630
K7GWPassword-Stealer ( 0057b8511 )
K7AntiVirusPassword-Stealer ( 0057b8511 )
ArcabitTrojan.Zusy.D74BF2
CyrenW32/MSIL_Agent.FUM.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/PSW.Agent.SHS
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan-PSW.MSIL.Convagent.gen
BitDefenderGen:Variant.Zusy.478194
AvastWin32:MalwareX-gen [Trj]
TencentWin32.Trojan.Ad.Pgil
SophosMal/Generic-S
F-SecureTrojan.TR/AD.TyphonSteal.mpbph
VIPREGen:Variant.Zusy.478194
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Zusy.478194 (B)
AviraTR/AD.TyphonSteal.mpbph
Antiy-AVLTrojan[PSW]/MSIL.Agent
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmVHO:Trojan-PSW.MSIL.Convagent.gen
GDataGen:Variant.Zusy.478194
GoogleDetected
McAfeeArtemis!7BC382A4271A
MAXmalware (ai score=86)
Cylanceunsafe
RisingStealer.Agent!8.C2 (CLOUD)
IkarusTrojan-Spy.Echelon
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Zusy.478194?

Zusy.478194 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment