Malware

Zusy.321407 removal

Malware Removal

The Zusy.321407 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.321407 virus can do?

  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Zusy.321407?


File Info:

name: A9ECBC7B0ABA68657ACB.mlw
path: /opt/CAPEv2/storage/binaries/3a18213c940269a46202869077b3da9d9cfc1c28d52632fa0632d4fe60b332e6
crc32: FC6EAE23
md5: a9ecbc7b0aba68657acb978c11968d73
sha1: 0f16ed94043ca753c6de27b25b7d044914059624
sha256: 3a18213c940269a46202869077b3da9d9cfc1c28d52632fa0632d4fe60b332e6
sha512: 64591873cf3a9ffb8b53fa1e948233f1eee949ac45492de696d530feafd1863686c91e6cebd552be6d8f17e6bdd171029d1bd5dbb5eb2a74742760a5b926c015
ssdeep: 6144:+M7Z4o4e2VW1DEeAiko0HrBYJQoKr9congt5vgP83Dm7dFje7fh2OZR4l:V4NTeAikvHrLoKAaPag28hl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14694E1313586C037E2AB01354AE5CB69693A7DA15B72A8C737C41BEE9EB02E1D730347
sha3_384: bdb68a37663b56afeb0a3345dcdbdccf9d7eb68536eaa8546e69e1dd80fe9a0488254a0338a8dc3e274863eb26dff8f4
ep_bytes: e8585f0000e989feffff8bff558bec5d
timestamp: 2009-03-28 06:09:52

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Office Word
FileVersion: 11.0.5604
InternalName: WinWord
LegalCopyright: Copyright © 1983-2003 Microsoft Corporation. All rights reserved.
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: WinWord.exe
ProductName: Microsoft Office 2003
ProductVersion: 11.0.5604
Translation: 0x0000 0x04e4

Zusy.321407 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.a9ecbc7b0aba6865
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.gc
McAfeeGenericRXMP-LM!A9ECBC7B0ABA
Cylanceunsafe
VIPREGen:Variant.Zusy.321407
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Cuegoe.1008
K7GWTrojan ( 005712881 )
K7AntiVirusTrojan ( 005712881 )
BitDefenderThetaGen:NN.ZexaF.36802.zu0@a03N7!mi
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDropper.Agent.QGO
APEXMalicious
ClamAVWin.Trojan.Agent-1363273
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.321407
NANO-AntivirusTrojan.Win32.Zusy.joceac
MicroWorld-eScanGen:Variant.Zusy.321407
AvastWin32:Agent-AUBD [Trj]
TencentTrojan.Win32.Agent.xe
TACHYONTrojan-Dropper/W32.Agent.424448.M
EmsisoftGen:Variant.Zusy.321407 (B)
BaiduWin32.Trojan-Dropper.Agent.ch
F-SecureBackdoor.BDS/Rogue.7735211
DrWebTrojan.MulDrop19.57448
ZillyaDropper.Agent.Win32.470060
TrendMicroTROJ_CUEGOE.SM
Trapminemalicious.high.ml.score
SophosTroj/Agent-BIRD
IkarusTrojan-Dropper.Win32.Agent
JiangminTrojanDropper.Agent.bpmi
VaristW32/Agent.TP.gen!Eldorado
AviraBDS/Rogue.7735211
Antiy-AVLTrojan[Backdoor]/Win32.Salgorea.gen
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDropper:Win32/Salgorea.AI!MTB
XcitiumApplication.Win32.Amonetize.NE@5te978
ArcabitTrojan.Zusy.D4E77F
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Zusy.321407
GoogleDetected
AhnLab-V3Dropper/Win32.Agent.R72198
Acronissuspicious
VBA32BScope.Backdoor.Salgorea
ALYacGen:Variant.Zusy.321407
MAXmalware (ai score=87)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_CUEGOE.SM
RisingDropper.Agent!1.AE54 (CLASSIC)
YandexTrojan.Agent!B+he2KLDDis
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.HLP!tr
AVGWin32:Agent-AUBD [Trj]
DeepInstinctMALICIOUS

How to remove Zusy.321407?

Zusy.321407 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment