Malware

Should I remove “Zusy.321255”?

Malware Removal

The Zusy.321255 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.321255 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup

How to determine Zusy.321255?


File Info:

crc32: DA853765
md5: 1177f57210c94b5c8743388f1f05804d
name: 1177F57210C94B5C8743388F1F05804D.mlw
sha1: 6f920ad1ee3e34cdbb964eba6fe724d6ef76231c
sha256: 5dd74d9ab077ae1dab0c673c6202b72beaef0faa8faf564132160b790d116113
sha512: 402c20a923047719b00ed0f756c71f314bbf9d64ceb8fab7db5b70eb8c55178b8224975354e3f9e783a2cbf5a413354f31ff69cc7397996097ae2dfd3483570a
ssdeep: 24576:zNnLjMx7SMCsVsehmdnxlfX/7/cziGzkjG3f:zJIxVsx/pXjrmw0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x672cx6e90x7801x6765x81eawww.jsjahz.com
FileVersion: 5.2.0.0
CompanyName: x7a0bx5c11QQ1767075269
Comments: x672cx6e90x7801x6765x81eawww.jsjahz.com
ProductName: x6613x8bedx8a00x7a0bx5e8f
ProductVersion: 5.2.0.0
FileDescription: x672cx6e90x7801x6765x81eawww.jsjahz.com
Translation: 0x0804 0x04b0

Zusy.321255 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005246d51 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
McAfeeGenericRXAK-UN!1177F57210C9
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Avkill.379ee66f
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.210c94
BaiduWin32.Trojan.KillAV.f
CyrenW32/Trojan.CLL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Disabler.NAV
APEXMalicious
AvastWin32:AutoRun-BRF [Wrm]
ClamAVWin.Trojan.Generic-9779041-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.321255
MicroWorld-eScanGen:Variant.Zusy.321255
TencentWin32.Trojan.Killav.Dvzr
Ad-AwareGen:Variant.Zusy.321255
SophosMal/Generic-S
ComodoWorm.Win32.Dropper.RA@1qraug
BitDefenderThetaGen:NN.ZexaF.34628.dr0@a8dJRllb
TrendMicroTROJ_KILLAV.SMIE
McAfee-GW-EditionBehavesLike.Win32.Generic.th
FireEyeGeneric.mg.1177f57210c94b5c
EmsisoftGen:Variant.Zusy.321255 (B)
SentinelOneStatic AI – Malicious PE
JiangminHeur:Trojan/AntiAV
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Avkill.E
GridinsoftTrojan.Win32.Gen.bot!i
ArcabitTrojan.Zusy.D4E6E7
GDataWin32.Application.FlyStudio.F
AhnLab-V3Trojan/Win32.RL_Killav.R371097
Acronissuspicious
MAXmalware (ai score=88)
MalwarebytesTrojan.MalPack.FlyStudio
TrendMicro-HouseCallTROJ_KILLAV.SMIE
RisingTrojan.Killav!1.9D3A (CLOUD)
IkarusTrojan.Win32.Disabler
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Disabler.NAT!tr
AVGWin32:AutoRun-BRF [Wrm]
Paloaltogeneric.ml
Qihoo-360Trojan.Win32.Made.I

How to remove Zusy.321255?

Zusy.321255 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment