Malware

About “Zusy.364231” infection

Malware Removal

The Zusy.364231 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.364231 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Creates a slightly modified copy of itself

How to determine Zusy.364231?


File Info:

crc32: B609EC71
md5: 68f12c72f9b8716ad340b1241286ebc7
name: 68F12C72F9B8716AD340B1241286EBC7.mlw
sha1: 74f9a6fbd3afa877c4b13322460a1b9804879211
sha256: eb470d20efe3f9369725a898e3fa468e1260f07cd7a555905d193ab83060cc6d
sha512: 4b62f0e9d9871fdc3f73720132b11cf18be5357faee99ee17817551e85bbb164a8cc9ecddcddb991a16b929c4e563c4b87f272ace09fadfd7e5fb831d3535177
ssdeep: 6144:UCCmIrPiSrceClr5tWSIb4g1OZl+dUMAADe5uAejfZnCLFYdxfsLPrPwo:amIripJHtW3vYWwQeJYALFYTfm
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Zusy.364231 also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.364231
FireEyeGeneric.mg.68f12c72f9b8716a
CAT-QuickHealTrojan.Glupteba
ALYacGen:Variant.Zusy.364231
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0053c3831 )
BitDefenderGen:Variant.Zusy.364231
K7GWTrojan ( 0053c3831 )
Cybereasonmalicious.bd3afa
BitDefenderThetaGen:NN.ZexaF.34804.FmZ@aak9Dng
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R049H0CAT21
AvastWin32:Trojan-gen
AlibabaTrojan:Win32/Injector.77e21348
AegisLabTrojan.Win32.Zusy.4!c
RisingTrojan.Generic@ML.92 (RDMK:LI8S6fHSvgs38PX/TTM+bw)
Ad-AwareGen:Variant.Zusy.364231
EmsisoftGen:Variant.Zusy.364231 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureHeuristic.HEUR/AGEN.1131762
TrendMicroPAK_Xed-10
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1131762
MicrosoftTrojan:Win32/Glupteba!ml
ArcabitTrojan.Zusy.D58EC7
GDataGen:Variant.Zusy.364231
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2706613
McAfeeArtemis!68F12C72F9B8
MAXmalware (ai score=87)
VBA32BScope.Trojan.Wacatac
MalwarebytesMalware.AI.4179110989
APEXMalicious
ESET-NOD32a variant of Win32/Injector.EAHK
IkarusTrojan.Win32.Injector
FortinetW32/Kryptik.FFP!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Trojan.Generic.HxMB758A

How to remove Zusy.364231?

Zusy.364231 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment