Malware

About “Zusy.370132” infection

Malware Removal

The Zusy.370132 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.370132 virus can do?

  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Attempts to modify browser security settings

How to determine Zusy.370132?


File Info:

crc32: B9119BE9
md5: 049164da57483d5b4336d2e6d766aa6d
name: 049164DA57483D5B4336D2E6D766AA6D.mlw
sha1: be4f521ce3c88bd4049aa30811dbad7088009c17
sha256: 0d869e7cdf91a82a68789a38021aafee89447af92025bdb32306f311a3075c18
sha512: 3bdcf03cde44f9541022256a5a54fe8918e2bee5f9f13083709a0171cac79b37d3c902c5565b42e27f82014c14e658f88adf5b5c2459b2bc08749bbca272e354
ssdeep: 24576:UgnbBUpPwYsIUMT99sELi8QDUWbVU/0BSMRwc:/tUpoYpUm9iSdmfRL
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright:
FileVersion: 1.0.0.0
CompanyName:
Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.eyuyan.com)
ProductName:
ProductVersion: 1.0.0.0
FileDescription:
Translation: 0x0804 0x04b0

Zusy.370132 also known as:

K7AntiVirusTrojan ( 004b4ad91 )
LionicTrojan.Win32.QQPass.i!c
Elasticmalicious (high confidence)
DrWebAdware.Cinmus.35664
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Generic.2919
ALYacGen:Variant.Zusy.370132
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 004b4ad91 )
Cybereasonmalicious.a57483
CyrenW32/A-4998212c!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FlyStudio.Injector.B potentially unwanted
APEXMalicious
AvastFileRepMalware
ClamAVWin.Worm.Mytob-270
Kasperskynot-a-virus:AdWare.Win32.Agent.gen
BitDefenderGen:Variant.Zusy.370132
NANO-AntivirusTrojan.Win32.NSPM.dokuqj
MicroWorld-eScanGen:Variant.Zusy.370132
TencentWin32.Trojan-qqpass.Qqrob.Eyb
Ad-AwareGen:Variant.Zusy.370132
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34170.jnLfaON85spb
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.049164da57483d5b
EmsisoftGen:Variant.Zusy.370132 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.gvjqq
AviraTR/Spy.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASCommon.FA
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Zusy.D5A5D4
GDataWin32.Application.PUPStudio.A
Acronissuspicious
McAfeeGenericRXAA-AA!049164DA5748
MAXmalware (ai score=88)
VBA32BScope.Trojan.Fuerboos
RisingTrojan.Agent!1.D0C2 (CLASSIC)
YandexTrojan.GenAsa!CtyK7sxHkR4
MaxSecureDropper.Dinwod.frindll
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Zusy.370132?

Zusy.370132 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment