Malware

Zusy.312447 (file analysis)

Malware Removal

The Zusy.312447 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.312447 virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.

How to determine Zusy.312447?


File Info:

crc32: 818D6AF5
md5: 67be3b1d66edb489de2d6b05d96f57a8
name: 67BE3B1D66EDB489DE2D6B05D96F57A8.mlw
sha1: 97d8659f596be2b90bcf7dc857813831b7f69223
sha256: 1e37f4672281c72069ae4c36db0cc458a1b262e97382516b44bc0247b2736dd1
sha512: fb22177802d309490f6834a3e4aa806c97a7f96ae83d00150831adc85c2550439daa296b517f3f4b154170acfa181ceb2373e91298847bdb6cca81191517a56b
ssdeep: 24576:doJBu2XV04jnHW8V8YcOa3sM6zlYzLhQ0zJ68VQWWRWqM:Ku4jH/cOcsvWkq3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1997-2020 Simon Tatham.
InternalName: PuTTY
FileVersion: Release 0.74 (with embedded help)
CompanyName: Simon Tatham
ProductName: PuTTY suite
ProductVersion: Release 0.74
FileDescription: SSH, Telnet and Rlogin client
OriginalFilename: PuTTY
Translation: 0x0809 0x04b0

Zusy.312447 also known as:

K7AntiVirusTrojan ( 005325ae1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
McAfeeArtemis!67BE3B1D66ED
SangforVirus_Suspicious.Win32.Sality.ae
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Swrort.12510c50
K7GWTrojan ( 005325ae1 )
Cybereasonmalicious.d66edb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Rozena.AMX.gen
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.Win32.Cometer.gen
BitDefenderGen:Variant.Zusy.312447
MicroWorld-eScanGen:Variant.Zusy.312447
Ad-AwareGen:Variant.Zusy.312447
SophosATK/Shellter-AD
BitDefenderThetaGen:NN.ZexaF.34608.bD0@aijJAHhi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.67be3b1d66edb489
EmsisoftGen:Variant.Zusy.312447 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1125217
MicrosoftTrojan:Win32/Swrort.A
ArcabitTrojan.Zusy.D4C47F
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Zusy.312447
MAXmalware (ai score=85)
MalwarebytesMachineLearning/Anomalous.96%
PandaTrj/Genetic.gen
RisingTrojan.Cometer!8.E150 (CLOUD)
YandexTrojan.Rozena!HzkpdhLd3Ls
IkarusTrojan.Win32.Rozena
MaxSecureWin.MxResIcn.Heur.Gen
FortinetW32/Rozena.AMX!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Swrort.HgIASQgA

How to remove Zusy.312447?

Zusy.312447 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment