Malware

Zusy.371170 removal

Malware Removal

The Zusy.371170 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.371170 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Zusy.371170?


File Info:

crc32: 7AFD0DC0
md5: 2a4480ac07ecbe8d0671ec947c1b84c6
name: 2A4480AC07ECBE8D0671EC947C1B84C6.mlw
sha1: 0402ab7b5665b4d2edfc39091ecfe57e8b64bce5
sha256: ff55279d5ef18ff4efb6cd662a7f94f4a5498ccaa2db27df946b6118a32a7c84
sha512: c878a53150e1649a393401dcbf2202ba59fcb0d5441ab8da848d9b4ac3b1cfdaf8f284ce975a56db436cf60d690eb3b1b73c171de270ef3a399e3fe1287595b2
ssdeep: 12288:g5udlKZoeTeV0hYpp7zXQeJGuveKGyrYfv1PShSJ+qUBAvLk:gMzKVTfkX9GuFrWv1Gs+VIk
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.371170 also known as:

DrWebTrojan.Inject4.8682
CynetMalicious (score: 90)
ALYacGen:Variant.Zusy.371170
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Bsymem.5168f851
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
CyrenW32/Trojan.MMFZ-1746
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Injector.EOWB
AvastWin32:DangerousSig [Trj]
ClamAVWin.Malware.Zusy-9841059-0
KasperskyTrojan.Win32.Bsymem.ydh
BitDefenderGen:Variant.Zusy.371170
ViRobotTrojan.Win32.Z.Graftor.738280.C
MicroWorld-eScanGen:Variant.Zusy.371170
Ad-AwareGen:Variant.Zusy.371170
SophosMal/Generic-R + Mal/EncPk-APY
Comodo.UnclassifiedMalware@0
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Zusy.371170
EmsisoftMalCert.A (A)
WebrootW32.Trojan.Gen
AviraTR/AD.Qbot.qpztw
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.Zusy.D5A9E2
GDataGen:Variant.Zusy.371170
AhnLab-V3Trojan/Win.Qakbot.R371607
McAfeeGenericRXAA-AA!2A4480AC07EC
MAXmalware (ai score=80)
VBA32BScope.Trojan.Bsymem
MalwarebytesBackdoor.Qbot
PandaTrj/Genetic.gen
RisingTrojan.Bsymem!8.FAE7 (CLOUD)
IkarusTrojan.Win32.Krypt
FortinetW32/EncPk.APY!tr
AVGWin32:DangerousSig [Trj]
Qihoo-360Win32/Trojan.Generic.HxkA3RsA

How to remove Zusy.371170?

Zusy.371170 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment