Malware

What is “Zusy.431103”?

Malware Removal

The Zusy.431103 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.431103 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid

How to determine Zusy.431103?


File Info:

name: 72E418F456EA465C671F.mlw
path: /opt/CAPEv2/storage/binaries/f59e7963e6a2a5bfa7b953fdf5b020d122bcab6640cae40f023dc1864f4a2a91
crc32: 79350B75
md5: 72e418f456ea465c671fae2670250eef
sha1: 0bc76d74ec4ce91a85d2abc453603aaa68bfee87
sha256: f59e7963e6a2a5bfa7b953fdf5b020d122bcab6640cae40f023dc1864f4a2a91
sha512: 3f453f6653bba52ddc329efdbe154d713b70ae28b6fab9f35abf1fd2764dc00cc239a5821a670aaf8cf10d1d190632969201d0b1c6768dc922965e6e06f0b682
ssdeep: 6144:VCkAzolDR52aZZDB8xZ9GeLIbgLVWuonNmIOY7Gw4CTaXEzZ/fz2U:rAsV2gZDBgZRIbgLVzRw4E3NL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T171F41246EB514E5AC0541534CCEB8AFDB9723CAAED075B5B33D4BF2736722148E12D24
sha3_384: aff48a430345320924c6ed7ae4740924c38578c202f0c53cfa2df9d11b2baecf71e7ff12a18f5d968f40e415d4fc8087
ep_bytes: 558bec6afe6878554a0068a043480064
timestamp: 2011-03-05 18:49:31

Version Info:

CompanyName: Torclt
FileDescription: Tor
FileVersion: 1.0.4.6
InternalName: tor.exe
LegalCopyright: Copyright (C) 2011
OriginalFilename: tor.exe
ProductName: Torclt
ProductVersion: 1.0.4.6
Translation: 0x000a 0x04b0

Zusy.431103 also known as:

BkavW32.AIDetect.malware2
LionicHeuristic.File.Generic.00×1!p
DrWebTrojan.Winlock.5553
MicroWorld-eScanGen:Variant.Zusy.431103
FireEyeGeneric.mg.72e418f456ea465c
McAfeePWS-Zbot.gen.fa
CylanceUnsafe
VIPREGen:Variant.Zusy.431103
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderThetaGen:NN.ZexaF.34698.SC0@aSIFK3ck
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
TrendMicro-HouseCallTROJ_RANSOM.JM
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.431103
AvastWin32:MalOb-CA [Cryp]
Ad-AwareGen:Variant.Zusy.431103
SophosMal/FakeAV-LX
ComodoSuspicious@#2gr5yhyhotm2i
ZillyaTrojan.PornoBlocker.Win32.2106
TrendMicroTROJ_RANSOM.JM
McAfee-GW-EditionBehavesLike.Win32.ZBot.bz
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zusy.431103 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.294
MicrosoftRansom:Win32/LockScreen.AO
GDataGen:Variant.Zusy.431103
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R4949
Acronissuspicious
VBA32BScope.Trojan.Winlock
ALYacGen:Variant.Zusy.431103
RisingMalware.Undefined!8.C (TFE:4:BWy4YAxxK5E)
IkarusTrojan-Spy.Win32.Zbot
FortinetW32/PornoBlocker.XED!tr
AVGWin32:MalOb-CA [Cryp]
Cybereasonmalicious.456ea4
PandaGeneric Malware

How to remove Zusy.431103?

Zusy.431103 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment