Malware

Zusy.315050 removal instruction

Malware Removal

The Zusy.315050 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.315050 virus can do?

  • Authenticode signature is invalid
  • Binary file triggered YARA rule
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Zusy.315050?


File Info:

name: 54F4AB5541C0BCEB937C.mlw
path: /opt/CAPEv2/storage/binaries/af7af50a9bd1dc33ff7157866f7792161487bbe7d5dd31fb4d78ec219f114ebb
crc32: 67B85B73
md5: 54f4ab5541c0bceb937c057a965e1647
sha1: 6e4aa5e56103dac77eea0eb2125650e4b5d7d9ec
sha256: af7af50a9bd1dc33ff7157866f7792161487bbe7d5dd31fb4d78ec219f114ebb
sha512: 25b6157532d4438d4ac4cc5bbbcc78d062a8f2d15bbcd94e8e115ecbe0ad4714cab2e54137f52ee752c7a21bb2c6cacc112c98c88547cbb47637a05eabd4c195
ssdeep: 768:CewRRzgT291lvLotXpUoImwKZZ+dZowUkfbZoxX:CewRJgTWPcImwLsb2oZ
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T173337D51764249B3D2892135D2E06F2E9FBD75220AE598C79FB25D0D1F319F0A23BB0B
sha3_384: 09e993cbe960ee36ceb2671078b1705fe3fa0926cec106f7b3a385631df719aee4541dfb61779f855a37151ab9fa6a97
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2020-03-16 07:56:00

Version Info:

0: [No Data]

Zusy.315050 also known as:

LionicTrojan.Win32.Generic.mEjk
MicroWorld-eScanGen:Variant.Zusy.315050
CAT-QuickHealTrojan.Win32CiR
SkyhighBackDoor-FEFJ!54F4AB5541C0
ALYacGen:Variant.Zusy.315050
Cylanceunsafe
ZillyaTrojan.Korplug.Win32.1306
SangforTrojan.Win32.Korplug.Vro8
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Korplug.8951103e
K7GWTrojan ( 0056eaf61 )
K7AntiVirusTrojan ( 0056eaf61 )
ArcabitTrojan.Zusy.D4CEAA
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Korplug.QS
TrendMicro-HouseCallTROJ_GEN.R06CC0PDO21
KasperskyHEUR:Trojan.Win32.Dllhijacker.gen
BitDefenderGen:Variant.Zusy.315050
AvastWin32:Korplug-D [Trj]
TencentMalware.Win32.Gencirc.115de9cd
EmsisoftGen:Variant.Zusy.315050 (B)
F-SecureHeuristic.HEUR/AGEN.1372673
DrWebTrojan.Loader.1139
VIPREGen:Variant.Zusy.315050
TrendMicroTROJ_GEN.R06CC0PDO21
FireEyeGen:Variant.Zusy.315050
SophosMal/Generic-S
JiangminTrojan.DllHijacker.di
GoogleDetected
AviraHEUR/AGEN.1372673
VaristW32/Korplug.S.gen!Eldorado
Antiy-AVLTrojan/Win32.Korplug
MicrosoftTrojan:Win32/Korplug!mclg
ZoneAlarmHEUR:Trojan.Win32.Dllhijacker.gen
GDataGen:Variant.Zusy.315050
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.C4196077
McAfeeBackDoor-FEFJ!54F4AB5541C0
MAXmalware (ai score=100)
VBA32Trojan.Wacatac
MalwarebytesFloxif.Virus.FileInfector.DDS
PandaTrj/CI.A
RisingTrojan.Generic@AI.86 (RDML:HwacVB+dg8fCbDPm72FhBw)
IkarusTrojan.Win32.Korplug
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Agent.4EBB!tr
BitDefenderThetaGen:NN.ZedlaF.36802.dq4@aWWzq1i
AVGWin32:Korplug-D [Trj]
DeepInstinctMALICIOUS

How to remove Zusy.315050?

Zusy.315050 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment