Malware

Zusy.327461 removal instruction

Malware Removal

The Zusy.327461 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.327461 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings

How to determine Zusy.327461?


File Info:

crc32: 333E91E0
md5: e85a34b0bd5876b42028949a7173f599
name: E85A34B0BD5876B42028949A7173F599.mlw
sha1: 08723f986e3e237e8ceeb3434e87957eb04fd0b1
sha256: f8f49df6927f9970030893c11de1386cd00be1407e9e244d7b9cba0d28f9d2b1
sha512: e4f2e6201bd8e3c604869c8dad9248688081b5ed559927cf927adeebd6090465d584304070ca186dbab92ed55a83d543d695ebf8613fec671cf34c40301e17c9
ssdeep: 49152:SaVLwo8EfPvqQHdK8iRynig8ydwYu09V8azN0x5bmz2fRKFFKmDuTAuk:xtFvq8piRynoYug8aC5UAKFw2ru
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2015
InternalName: iPhoneMonitor.exe
FileVersion: 1.0.0.0
ProductName: x5fc3x84ddiReservex5e93x5b58x76d1x63a7x5668
ProductVersion: 1.0.0.0
FileDescription: x5fc3x84ddiReservex5e93x5b58x76d1x63a7x5668
OriginalFilename: iPhoneMonitorr.exe
Translation: 0x0804 0x04b0

Zusy.327461 also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Zusy.327461
FireEyeGeneric.mg.e85a34b0bd5876b4
McAfeeArtemis!E85A34B0BD58
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0051b8b01 )
BitDefenderGen:Variant.Zusy.327461
K7GWTrojan ( 0051b8b01 )
Cybereasonmalicious.0bd587
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Inject.ameun
AlibabaTrojan:Win32/Inject.39469347
NANO-AntivirusTrojan.Win32.Zusy.euxbwf
AegisLabTrojan.Win32.Generic.4!c
Ad-AwareGen:Variant.Zusy.327461
SophosML/PE-A + Mal/Wonton-X
ZillyaTrojan.Injector.Win32.572243
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Zusy.327461 (B)
AviraTR/Injector.tutkh
MAXmalware (ai score=99)
Antiy-AVLTrojan/Win32.TSGeneric
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Zusy.D4FF25
ZoneAlarmTrojan.Win32.Inject.ameun
GDataGen:Variant.Zusy.327461
CynetMalicious (score: 90)
BitDefenderThetaGen:NN.ZexaF.34804.SoNfae@n4ckj
ALYacGen:Variant.Zusy.327461
VBA32BScope.Trojan.Tiggre
MalwarebytesMalware.Heuristic.1003
ESET-NOD32a variant of Win32/Injector.DJSP
TencentMalware.Win32.Gencirc.10bab4f6
YandexTrojan.GenAsa!IpBE7ksLD/g
SentinelOneStatic AI – Suspicious PE
FortinetW32/Injector.VGKR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Zusy.327461?

Zusy.327461 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment