Malware

About “Zusy.487797 (B)” infection

Malware Removal

The Zusy.487797 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.487797 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Zusy.487797 (B)?


File Info:

name: D58FEF535261D91898D0.mlw
path: /opt/CAPEv2/storage/binaries/1641cc8f4574d6dee922ebad91ef0fb05e1aa7df4441e5d22c4b4ca63df796b4
crc32: 0B3E2D55
md5: d58fef535261d91898d001828d34e5ee
sha1: c9586117ea90e23d915d86032829a45e770070b9
sha256: 1641cc8f4574d6dee922ebad91ef0fb05e1aa7df4441e5d22c4b4ca63df796b4
sha512: 2dce6776a8cf1864ac8e6db9eac6131230e638fa800b19720cac632aa7d4ae05a501b1521a0a302b044f9cbe48fbd469bf3af2591dc7cde0f47c20a4fbeb54d7
ssdeep: 24576:sWixC7Irstm7UEdIaoyFcZ7l58A91tBZw86QdoCKm7UE33+v+YDWRDTqO:XbtmFdcZx58A9vwVQNKmv+yi
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T19695C00D91499C33C1B4923239A4772E349EA3F2D0FE234E3FF81579A0F196B95D8696
sha3_384: 79f2e77ba4956ff3f3f05ea75a99071f9c0a48ba169faf7d16b6f93a802b6b0391019556d5f82d9c36fd7f88a5ec6384
ep_bytes: 8bff558bec837d0c017505e8560d0000
timestamp: 2012-11-07 16:19:05

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft® InfoTech IR Local DLL
FileVersion: 5.70.51021.0
InternalName: ITIRCL55
LegalCopyright: Copyright © Microsoft Corp.
OriginalFilename: ITIRCL55.DLL
ProductName: Microsoft ® Infotech Technology Library
ProductVersion: 5.70.51021.0
Translation: 0x0409 0x04b0

Zusy.487797 (B) also known as:

BkavW32.AIDetectMalware
AVGWin32:Patched-AWX [Trj]
Elasticmalicious (high confidence)
DrWebWin32.Beetle.3
MicroWorld-eScanGen:Variant.Zusy.487797
FireEyeGen:Variant.Zusy.487797
VIPREGen:Variant.Zusy.487797
K7AntiVirusTrojan ( 005ab4bf1 )
K7GWTrojan ( 005ab4bf1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Patched.NKM
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:Patched-AWX [Trj]
KasperskyVirus.Win32.Senoval.a
BitDefenderGen:Variant.Zusy.487797
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
RisingTrojan.Generic@AI.100 (RDML:uKwCEe8KfVH3b0HsD5TCDQ)
EmsisoftGen:Variant.Zusy.487797 (B)
F-SecureTrojan.TR/Patched.Gen
IkarusTrojan.Win32.Patched
GoogleDetected
AviraTR/Patched.Gen
MAXmalware (ai score=84)
MicrosoftVirus:Win32/Senoval.HNS!MTB
ArcabitTrojan.Zusy.D77175
ZoneAlarmVirus.Win32.Senoval.a
GDataGen:Variant.Zusy.487797
VaristW32/Patched.GQ1.gen!Eldorado
AhnLab-V3Malware/Win.Generic.R605977
ALYacGen:Variant.Zusy.487797
VBA32BScope.TrojanDownloader.Emotet
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan.Win32.Pathced_ya.16001052
SentinelOneStatic AI – Suspicious PE
FortinetW32/Patched.IP!tr

How to remove Zusy.487797 (B)?

Zusy.487797 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment