Malware

Ser.Zusy.2285 removal instruction

Malware Removal

The Ser.Zusy.2285 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Zusy.2285 virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Uses suspicious command line tools or Windows utilities

How to determine Ser.Zusy.2285?


File Info:

crc32: 7BADFCC6
md5: 31698d5082975fc77007a7ba41f5e971
name: 31698D5082975FC77007A7BA41F5E971.mlw
sha1: eebb422702cb799abc3b280b75b0ffdb3c4505d8
sha256: 3b1a6583f368ac077ac58496c75c2d43d074b3064023ca249a45688e65d5419d
sha512: c7fba8c6afc1d843bab88e6e9891629cd634915a4a0b66850e2eb77b0fc821b38211d4198078878cfa5274e6aed0b3187e00a4ce110567758daa4ebdf7449a3a
ssdeep: 98304:apqol6qazh+78Wftj4puoeuaKhlrH9L7TRZ+ZHJtj/IcikcskwvOC+:y0/zh+wWftLoeghlpzX+ZHTgZwvk
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C)360.cn ALL Rights Reserved.
FileVersion: 2.0.0.0
CompanyName: www.360.cn
Comments: x5b89x5168x9632x62a4x4e2dx5fc3x6a21x5757
ProductName: x5b89x5168x9632x62a4x4e2dx5fc3x6a21x5757
ProductVersion: 2.0.0.0
FileDescription: x5b89x5168x9632x62a4x4e2dx5fc3x6a21x5757
Translation: 0x0804 0x04b0

Ser.Zusy.2285 also known as:

K7AntiVirusTrojan ( 005246d51 )
LionicTrojan.Win32.EquationDrug.4!c
Elasticmalicious (high confidence)
ClamAVWin.Malware.Temr-7070541-0
CAT-QuickHealTrojan.Flystudio.100458
ALYacGen:Variant.Ser.Zusy.2285
CylanceUnsafe
ZillyaTrojan.EquationDrug.Win32.614
SangforTrojan.Win32.Save.a
AlibabaBackdoor:Win32/ShadowBrokers.a95dd8bb
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.082975
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyTrojan.Win32.EquationDrug.vh
BitDefenderGen:Variant.Ser.Zusy.2285
NANO-AntivirusTrojan.Win32.EquationDrug.fmsyqs
MicroWorld-eScanGen:Variant.Ser.Zusy.2285
TencentWin32.Trojan.Equationdrug.Lhnd
Ad-AwareGen:Variant.Ser.Zusy.2285
SophosMal/Generic-S
ComodoWorm.Win32.Dropper.RA@1qraug
BitDefenderThetaGen:NN.ZexaF.34236.@t0@aSmI9feb
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
FireEyeGeneric.mg.31698d5082975fc7
EmsisoftGen:Variant.Ser.Zusy.2285 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1114106
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Ser.Zusy.D8ED
GDataWin32.Trojan.PSE.12FI8JT
AhnLab-V3Trojan/Win32.Agent.R246443
Acronissuspicious
McAfeeGenericR-OYJ!31698D508297
MAXmalware (ai score=100)
VBA32Trojan.Win64.Miner
MalwarebytesTrojan.MalPack.FlyStudio
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.100 (RDML:P38w/h1l2OhDleXI+kdZng)
YandexTrojan.GenAsa!bSYHbNEeZGQ
MaxSecureTrojan.Malware.11063193.susgen
FortinetW32/EquationDrug.VH!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Ser.Zusy.2285?

Ser.Zusy.2285 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment