Malware

Zusy.321102 removal guide

Malware Removal

The Zusy.321102 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.321102 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)

How to determine Zusy.321102?


File Info:

name: 1847EC35DE2BF91BE519.mlw
path: /opt/CAPEv2/storage/binaries/0307467140e352bccc0a1b6974033c6958a1cb0c5b0fad24b1fb37a390c675e5
crc32: A82BCD82
md5: 1847ec35de2bf91be519216e52142180
sha1: b031aa94640596043f5241b5421162ba70416848
sha256: 0307467140e352bccc0a1b6974033c6958a1cb0c5b0fad24b1fb37a390c675e5
sha512: 791a74c9dc91aadf521348561384be2060cddad013063840fd697549f2e730a52b9ac8e31efe5d336e2b39ca80a20aa3dfe2eb572cf9ef124e9c0ebc69823c96
ssdeep: 768:M3ncJu5hBXF2pmiq2V41xNmAFgGyi4XwP13GT9W28z/zMp5xAFiE3s:M3cJu5hBVWq2kN6LXwPVGT9lgA5gs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10D83072BE78604B5DB368D30DEEA6A33EA267D85291CD48B26C0DF19447361AF43135F
sha3_384: 70662238742692a93e7c04ac5b3e0147e5f518fdd385e0c3f52286cf9bca9e1a29fdb014e9f49ec22cd6133a0d79fb55
ep_bytes: 558bec6aff68e0b640006810a5400064
timestamp: 2014-04-01 12:09:40

Version Info:

Comments: Generic Host Process for Win32 Services.
CompanyName: Microsoft Corporation
FileDescription: Generic Host Process for Win32 Services
FileVersion: 5.1.2600.5512
InternalName: svchost
LegalCopyright: ? Microsoft Corporation. All rights reserved.
LegalTrademarks:
OriginalFilename: svchost.exe
PrivateBuild:
ProductName: Microsoft? Windows? Operating System
ProductVersion: 5.1.2600.5512
SpecialBuild:
Translation: 0x0409 0x04b0

Zusy.321102 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Agent.lVBk
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.321102
FireEyeGen:Variant.Zusy.321102
CAT-QuickHealTrojan.Beaugrit.B4
McAfeeTrojan-FDXK!1847EC35DE2B
CylanceUnsafe
SangforTrojan.Win32.Zusy.84709
K7AntiVirusTrojan ( 0040f8921 )
AlibabaTrojan:Win32/Generic.ec33c2b0
K7GWTrojan ( 0040f8921 )
Cybereasonmalicious.5de2bf
ArcabitTrojan.Zusy.D4E64E
BaiduWin32.Trojan.Agent.bw
VirITTrojan.Win32.Generic.AHZO
SymantecSMG.Heur!gen
ESET-NOD32Win32/Agent.VVT
APEXMalicious
ClamAVWin.Trojan.Agent-1108404
KasperskyTrojan.Win32.Agent.icbq
BitDefenderGen:Variant.Zusy.321102
NANO-AntivirusTrojan.Win32.TrjGen.cstxhy
SUPERAntiSpywareTrojan.Agent/Gen-FakeMS
AvastWin32:Trojan-gen
TencentTrojan.Win32.Agent.agz
Ad-AwareGen:Variant.Zusy.321102
TACHYONTrojan/W32.Agent.86079.C
SophosMal/Generic-S + Troj/Agent-AHRL
ComodoTrojWare.Win32.Agent.ICBQ@59gfsi
DrWebTrojan.Siggen6.6093
ZillyaTrojan.Agent.Win32.456007
McAfee-GW-EditionTrojan-FDXK!1847EC35DE2B
EmsisoftGen:Variant.Zusy.321102 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Agent.igbj
AviraTR/Crypt.FKM.Gen
KingsoftWin32.Troj.Agent.ic.(kcloud)
MicrosoftTrojan:MSIL/Bladabindi
GDataGen:Variant.Zusy.321102
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Generic.R95723
BitDefenderThetaGen:NN.ZexaF.34638.fq1@ay7fPbfb
ALYacGen:Variant.Zusy.321102
MAXmalware (ai score=100)
VBA32Trojan.Agent
RisingTrojan.Beaugrit!8.3B5 (CLOUD)
YandexTrojan.FKM!o0KXg78nXQg
IkarusTrojan.Crypt
FortinetW32/Dx.CZN!tr
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Zusy.321102?

Zusy.321102 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment