Malware

About “Zusy.101395” infection

Malware Removal

The Zusy.101395 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.101395 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • The following process appear to have been packed with Themida: 7BDAE0E6878E2D81293F202DF2A9A147.mlw
  • Network activity detected but not expressed in API logs
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.101395?


File Info:

crc32: 5AC604A6
md5: 7bdae0e6878e2d81293f202df2a9a147
name: 7BDAE0E6878E2D81293F202DF2A9A147.mlw
sha1: 7777a9ec5b5d22191b223d8f898df758aff18c89
sha256: 3b4572f0a1f8506c664516433d70ec82043bc22671da9989932a6c34bee39c5f
sha512: 5e3af01ecb807eeac0636efb2fa214adf2271e07e976bd2fefaa96c138eba6fa6825ba6efc33725e6936487fb6143b50336e2464033c54cd3c273b4f18207870
ssdeep: 24576:SbmGcCpvKA4KZEllv0+ORGUGB5tBLk3tRvZsWC:SqGNpvKA4K2vkwUGB56Rva
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: 1.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: 1.exe

Zusy.101395 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.101395
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
Cybereasonmalicious.6878e2
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Themida.GSF
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.101395
MicroWorld-eScanGen:Variant.Zusy.101395
Ad-AwareGen:Variant.Zusy.101395
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.Agent.COC@52vn2u
BitDefenderThetaGen:NN.ZexaF.34692.jz0aaCIOb1m
TrendMicroTROJ_GEN.R005C0WEU21
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.7bdae0e6878e2d81
EmsisoftGen:Variant.Zusy.101395 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1102889
eGambitUnsafe.AI_Score_99%
MicrosoftProgram:Win32/Wacapew.C!ml
GridinsoftTrojan.Heur!.038100A1
GDataGen:Variant.Zusy.101395
AhnLab-V3Trojan/Win.Generic.C4496599
McAfeeArtemis!7BDAE0E6878E
MAXmalware (ai score=88)
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R005C0WEU21
RisingMalware.Heuristic!ET#97% (RDMK:cmRtazpE2eE28yIeN5ey9eY+E055)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen

How to remove Zusy.101395?

Zusy.101395 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment