Malware

About “Zusy.511341” infection

Malware Removal

The Zusy.511341 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.511341 virus can do?

  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.511341?


File Info:

name: 83933A594157E1182A67.mlw
path: /opt/CAPEv2/storage/binaries/5f613455fa20209f70d1f06361a1c317755b1afef6c264db5a1d38a3c69632be
crc32: E27F2A56
md5: 83933a594157e1182a67a4a561860f1b
sha1: 34b4e3effc16d6f311673dbbcb0e27a2d501230a
sha256: 5f613455fa20209f70d1f06361a1c317755b1afef6c264db5a1d38a3c69632be
sha512: de34d464ea40912402d59683c676c4511ba9362d32504a81ecc9740018818902bb09f5c77c7479effae148755c776b38790246288ec442347796352f576c60f0
ssdeep: 49152:J/4HzVEBiTZaqdwk0c05HGiO/6222WWWWx22O:l4ZEBiYqdwkLcHHO/6222WWWWx22O
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AC85E113FA9384FAC325157129AA1339BEF4DF014E209A93E7A0FD792C32595D63B24D
sha3_384: d077424aa6836051c2da7f9df85febd68f8f029af3469936862b0f474300c959338ead0561a91be690ef7235495936b5
ep_bytes: 558bec6aff68a8e65600689cd6470064
timestamp: 2013-04-05 06:12:13

Version Info:

FileVersion: 1.0.0.0
FileDescription: 暗黑
ProductName: 无名
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 暗黑
Translation: 0x0804 0x04b0

Zusy.511341 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.lq3h
ElasticWindows.Generic.Threat
MicroWorld-eScanGen:Variant.Zusy.511341
ClamAVWin.Trojan.Flystudio-9943951-0
FireEyeGeneric.mg.83933a594157e118
SkyhighBehavesLike.Win32.Generic.tc
McAfeeGenericRXEM-ZT!83933A594157
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.ffc16d
BitDefenderThetaGen:NN.ZexaF.36680.Xr0@aiRmcDbb
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.Exnet.gen
AlibabaTrojan:Win32/Generic.5534c52b
AvastWin32:Evo-gen [Trj]
TACHYONTrojan/W32.Agent.1851392.CT
F-SecureTrojan:W32/DelfInject.R
ZillyaTrojan.GenericML.Win32.47461
TrendMicroTROJ_GEN.R002C0PKL23
SophosGeneric Reputation PUA (PUA)
IkarusTrojan.Win32.Agent
WebrootTrojan.Dropper.Gen
GoogleDetected
Antiy-AVLTrojan/Win32.FlyStudio.a
XcitiumWorm.Win32.Dropper.RA@1qraug
ArcabitTrojan.Zusy.D7CD6D
ZoneAlarmVHO:Trojan.Win32.Exnet.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
VaristW32/Trojan.ISO.gen!Eldorado
AhnLab-V3Malware/Win.Generic.C5546077
ALYacGen:Variant.Zusy.511341
MAXmalware (ai score=86)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PKL23
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.PHP!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Zusy.511341?

Zusy.511341 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment