Malware

Zusy.501567 (file analysis)

Malware Removal

The Zusy.501567 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.501567 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Zusy.501567?


File Info:

name: BF41162268277E34D44C.mlw
path: /opt/CAPEv2/storage/binaries/7a5453fb6dfc7d5f267225a31cae374fb1e521d27ce0ba775f289a92f800ed49
crc32: 806451D0
md5: bf41162268277e34d44cde47f9355008
sha1: 2f925b0bd611813c22f0696f3a13b688d54a2b0e
sha256: 7a5453fb6dfc7d5f267225a31cae374fb1e521d27ce0ba775f289a92f800ed49
sha512: bc64122a56562c0ddae425239275500f1e254833912e7e8fae2ebaf8a2e236aeea8cb8ae305e0678698be8c6b88bfed93cfdb0a45c67abde481a5debb1e66e6c
ssdeep: 24576:Q3Q3uQACdOryrOb7dXirOj6hYP1vEI34U/2yzJ9bmQLD3iBijnxm0MCv3cUK:2euoOr5pr62dvEZ+2yTJeBitOCv3c
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C4757C4797624F73C3A43F35B4D7002F52B1C7327926EF1B361F54926D06329CA9A2AA
sha3_384: 560990cc208ca5b9a811f99b0b7d2c14c055b880e82d20aa0addae4878899a806ca57fbcb43393e2d19392e78aba1842
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-09-18 01:48:37

Version Info:

CompanyName:
FileDescription:
FileVersion: 16.10.31418.88
InternalName: VisualStudio.Shell.Framework.dll
LegalCopyright: © All rights reserved.
OriginalFilename: VisualStudio.Shell.Framework.dll
ProductName:
ProductVersion:
Assembly Version: 16.0.0.0
Translation: 0x0000 0x04b0

Zusy.501567 also known as:

ClamAVWin.Packed.Uztuby-10009381-0
ALYacGen:Variant.Zusy.501567
MalwarebytesBackdoor.DCRat
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005690671 )
BitDefenderGen:Variant.Zusy.501567
K7GWTrojan ( 005690671 )
Cybereasonmalicious.bd6118
ArcabitTrojan.Zusy.D7A73F
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.AJQX
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.MSIL.Disco.gen
MicroWorld-eScanGen:Variant.Zusy.501567
F-SecureHeuristic.HEUR/AGEN.1323342
VIPREGen:Variant.Zusy.501567
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.bf41162268277e34
EmsisoftGen:Variant.Zusy.501567 (B)
IkarusTrojan.MSIL.Crypt
JiangminTrojan.MSIL.aotqv
GoogleDetected
AviraHEUR/AGEN.1323342
MAXmalware (ai score=80)
MicrosoftProgram:Win32/Wacapew.C!ml
ZoneAlarmHEUR:Trojan-PSW.MSIL.Disco.gen
GDataGen:Variant.Zusy.501567
VaristW32/MSIL_Agent.FVY.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.C5484342
DeepInstinctMALICIOUS
Cylanceunsafe
RisingTrojan.Dnoper!8.10CB3 (TFE:dGZlOg3hFw/p7lyDRw)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZemsilF.36792.Kn0@ayZxHzb
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Zusy.501567?

Zusy.501567 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment