Malware

Zusy.321965 removal tips

Malware Removal

The Zusy.321965 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.321965 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the Kovter malware family

How to determine Zusy.321965?


File Info:

name: A61EFDFF250D05104733.mlw
path: /opt/CAPEv2/storage/binaries/4e6c4fc8385556490750f1fca5d4050326ed87a2bc431a6f0951e903f6accf96
crc32: EC0BD097
md5: a61efdff250d05104733b8d79140a9ae
sha1: fec6b36243c1b2bb1484060b59932641de845684
sha256: 4e6c4fc8385556490750f1fca5d4050326ed87a2bc431a6f0951e903f6accf96
sha512: 229de1453633d825839360ce0d0981943f1110d1fae975a5f546d4f11f7fbc43af20b93b054c61105e52bd1ac9720cf0014ac6649693aad2f933ea97920457dc
ssdeep: 6144:Wb8j+nGJYZNPl7BQHwLIu95eh/A8/5Zbyrf5BK2R3Qk8ZjfPtd++fmE0i:Wbn7NPV8QUMf3K2ByjuE0i
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10D942976F340E637D82518B8CE0FE3E1A469F6302D349C57B6E51F4C58B5683AA2B643
sha3_384: 7db28af1f0e66088ba6f3e930349e0b30de9e22b4e01f10e36e7dc1161235a5632b66cbe25b044481e3ddfed6f57ee4b
ep_bytes: 558bec83c4f4b890b60d00e850affaff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Zusy.321965 also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.321965
FireEyeGeneric.mg.a61efdff250d0510
ALYacGen:Variant.Zusy.321965
CylanceUnsafe
ZillyaTrojan.Kovter.Win32.8191
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004ffb0e1 )
K7GWTrojan ( 004ffb0e1 )
Cybereasonmalicious.f250d0
BitDefenderThetaGen:NN.ZelphiF.34646.AyW@auwkYNf
CyrenW32/Kovter.AK.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kovter.I
APEXMalicious
ClamAVWin.Packed.Alphaeon-9783095-0
KasperskyTrojan.Win32.Kovter.ajst
BitDefenderGen:Variant.Zusy.321965
NANO-AntivirusTrojan.Win32.Delphi.ehynrj
AvastSf:ShellCode-AO [Trj]
Ad-AwareGen:Variant.Zusy.321965
EmsisoftGen:Variant.Zusy.321965 (B)
ComodoTrojWare.Win32.Kovter.R@8f5pqh
VIPREGen:Variant.Zusy.321965
McAfee-GW-EditionBehavesLike.Win32.Ipamor.gh
Trapminesuspicious.low.ml.score
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.Kovter
GDataGen:Variant.Zusy.321965
GoogleDetected
AviraDR/Delphi.Gen
Antiy-AVLTrojan/Generic.ASMalwS.45ED
ArcabitTrojan.Zusy.D4E9AD
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Kovter.R294268
McAfeeArtemis!A61EFDFF250D
MAXmalware (ai score=87)
MalwarebytesGeneric.Trojan.Malicious.DDS
RisingTrojan.Kovter!1.A7CF (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kovter.I!tr
AVGSf:ShellCode-AO [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Zusy.321965?

Zusy.321965 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment