Malware

Should I remove “Zusy.523872”?

Malware Removal

The Zusy.523872 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.523872 virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.523872?


File Info:

name: 1747C63C47CD0836002A.mlw
path: /opt/CAPEv2/storage/binaries/ca7c658c414410feb50ac0aa36163e1bf8f0d474fa2128376af306d28e0c3aec
crc32: ED6D0F73
md5: 1747c63c47cd0836002ac19270bb3ea3
sha1: f2ca9cac17980a22fb9caf01a6514b4f9f58e137
sha256: ca7c658c414410feb50ac0aa36163e1bf8f0d474fa2128376af306d28e0c3aec
sha512: 460f6849cd6bc576e372649b12893484a2e646b3e66f861202f0d7cf1d88f8e9b4d3fec491bbcd6a5047fdc7ebb63cf5eb528ca63ed644b004140b05537dc4e4
ssdeep: 24576:R3qjyAS6B87sH5HK29w/g4opnWV1NLDIay94QWai/+T+JGTDNCbMHONhrQpS:RHNHJpG+ONCwHOuS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T124C54A13F952C4A1D2041A30C9AB03F979385F51D9628A47F7ACFE6BBF72261D617A0C
sha3_384: 3424e666d7a3befa2119874a4b12188eee414f9e6b4ef2d738a7ffd0cb19eac3468d3f348dce878674e68928ad9be4fd
ep_bytes: 558bec6aff68307d610068f0b8510064
timestamp: 2013-04-12 19:33:01

Version Info:

0: [No Data]

Zusy.523872 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lwgB
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.523872
FireEyeGeneric.mg.1747c63c47cd0836
SkyhighBehavesLike.Win32.Dropper.vm
McAfeeArtemis!1747C63C47CD
Cylanceunsafe
SangforTrojan.Win32.Agent.V5yj
K7AntiVirusAdware ( 005071f51 )
AlibabaTrojanPSW:Win32/MalwareX.be6504f4
K7GWAdware ( 005071f51 )
CrowdStrikewin/malicious_confidence_90% (W)
ArcabitTrojan.Zusy.D7FE60
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Trojanx-9951053-0
BitDefenderGen:Variant.Zusy.523872
AvastWin32:MalwareX-gen [Trj]
SophosGeneric Reputation PUA (PUA)
F-SecureTrojan.TR/Crypt.XPACK.Gen7
VIPREGen:Variant.Zusy.523872
Trapminesuspicious.low.ml.score
EmsisoftGen:Variant.Zusy.523872 (B)
IkarusTrojan-PSW.QQpass
VaristW32/Trojan.CLL.gen!Eldorado
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Win32.FlyStudio.a
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Trojan.PSE.1GX9Q8C
GoogleDetected
BitDefenderThetaGen:NN.ZexaF.36608.IsZ@aaNSWeh
ALYacGen:Variant.Zusy.523872
MAXmalware (ai score=89)
VBA32BScope.Trojan.Wacatac
MalwarebytesGeneric.Malware.AI.DDS
TrendMicro-HouseCallTROJ_GEN.R002H0CKS23
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/CoinMiner.PHP!tr
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.c17980
DeepInstinctMALICIOUS

How to remove Zusy.523872?

Zusy.523872 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment