Malware

Zusy.471160 removal guide

Malware Removal

The Zusy.471160 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.471160 virus can do?

  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.471160?


File Info:

name: E01F2CC8213FCE4885A4.mlw
path: /opt/CAPEv2/storage/binaries/6394d55aeb6c2c6d940dabf95d9b944cdf14ca9ee26f52d7e10a9e709d8308ba
crc32: 3EE5BFE5
md5: e01f2cc8213fce4885a47b9fde1d1533
sha1: 3afede4d08c5852205c873aef04d633c91653d2a
sha256: 6394d55aeb6c2c6d940dabf95d9b944cdf14ca9ee26f52d7e10a9e709d8308ba
sha512: 8253ee407aaaa16d8cfeda967f04850f796c02bc2861834d94c6491fad888e48c10f01a9391b7fdf0e06bec173c0ff0d1aad22cc09de1516d1445e0a7fb15295
ssdeep: 24576:klLNz9KcZzrGYdpzpZqdH3xyW1LuePRO2+oRcYIN4FtxMuddibF5hUSINAkxxMI9:kxpmdhpvPQ2+UcYI8ibfhwBRG6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T161C5B006A2164479E55861304DB73334F938FA531926AA83B7E4FE1DAF3B9A0D377318
sha3_384: f1ead1dcbc2fac7a5dc5031ff85ce576a280482ff49724ecc61fe8fa47a9ecdb55759a406ed40d492102e1a948c6b0da
ep_bytes: 558bec6aff6830996200688c9c4a0064
timestamp: 2013-03-02 03:41:29

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 老牛免费买药
ProductVersion: 1.0.0.0
CompanyName: 老牛
LegalCopyright: 老牛 版权所有
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Zusy.471160 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.471160
FireEyeGeneric.mg.e01f2cc8213fce48
CAT-QuickHealRisktool.Flystudio.17330
SkyhighBehavesLike.Win32.Generic.vh
ALYacGen:Variant.Zusy.471160
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.d08c58
ArcabitTrojan.Zusy.D73078
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Zusy.471160
SophosGeneric ML PUA (PUA)
F-SecureTrojan:W32/DelfInject.R
VIPREGen:Variant.Zusy.471160
EmsisoftGen:Variant.Zusy.471160 (B)
IkarusTrojan.Rogue
GoogleDetected
Antiy-AVLTrojan/Win32.FlyStudio.a
Kingsoftmalware.kb.a.908
XcitiumWorm.Win32.Dropper.RA@1qraug
MicrosoftProgram:Win32/Wacapew.C!ml
GDataWin32.Trojan.PSE.1H6ZYWO
VaristW32/S-47c1ea66!Eldorado
McAfeeGenericRXEP-MR!E01F2CC8213F
MAXmalware (ai score=85)
VBA32BScope.Trojan.BtcMine
Cylanceunsafe
SentinelOneStatic AI – Malicious PE
FortinetW32/CoinMiner.PHP!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Zusy.471160?

Zusy.471160 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment