Malware

Should I remove “Zusy.521164”?

Malware Removal

The Zusy.521164 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.521164 virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.521164?


File Info:

name: ED4F7FFA634B8EF681C0.mlw
path: /opt/CAPEv2/storage/binaries/16286cdca762ea5cda955aece099edc08c60d8beef70612284167b4ae1e20b25
crc32: 440C9CE0
md5: ed4f7ffa634b8ef681c089ab857a6884
sha1: bb84b9b14a93caf9c64bc1bef9cb6559b7ef1e73
sha256: 16286cdca762ea5cda955aece099edc08c60d8beef70612284167b4ae1e20b25
sha512: 734f41eb37de207c725b43da0979e82afb6ceaae3a08df8a51763855ef7f6348b5e07db925bc55ad7ced7658834eae0f3719493761e3ca300c90f34059196820
ssdeep: 24576:oMoWRHYkHdUy0/v0j6xCFnLtbPIi9hHQG3LE:ofk1yZ4NLt72H
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T160459D12F6D240F2C705253009A6673ABB75DF964F258FCBE394ED381D33290997B26A
sha3_384: d4c121ac8b50f8d344fbc07a4ea1673db1cf6eae3902629a7251a1aa7a1a8d9e611a0f8a34513d9db11303e2b857fb48
ep_bytes: 558bec6aff68d8f34f0068b8384b0064
timestamp: 2013-03-27 10:07:17

Version Info:

FileVersion: 1.9.0.0
FileDescription: www.wk7b.com
ProductName: 威客奇兵
ProductVersion: 1.9.0.0
CompanyName: WK7B.COM
LegalCopyright: WK7B.COM 版权所有
Comments: wzw@wk7b.com
Translation: 0x0804 0x04b0

Zusy.521164 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.521164
CAT-QuickHealTrojan.Antavmu.20290
SkyhighBehavesLike.Win32.Generic.th
McAfeeGenericRXAA-AA!ED4F7FFA634B
MalwarebytesGeneric.Malware.AI.DDS
Cybereasonmalicious.14a93c
BaiduWin32.Adware.Generic.k
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Trojanx-9951053-0
Kasperskynot-a-virus:VHO:NetTool.Win32.Convagent.gen
BitDefenderGen:Variant.Zusy.521164
AvastWin32:Dropper-gen [Drp]
SophosGeneric ML PUA (PUA)
FireEyeGeneric.mg.ed4f7ffa634b8ef6
EmsisoftGen:Variant.Zusy.521164 (B)
VaristW32/Trojan.CLL.gen!Eldorado
Antiy-AVLTrojan/Win32.FlyStudio.a
MicrosoftProgram:Win32/Wacapew.C!ml
XcitiumTrojWare.Win32.Agent.OSCF@5rs7jr
ArcabitTrojan.Zusy.D7F3CC
ZoneAlarmnot-a-virus:VHO:NetTool.Win32.Convagent.gen
GDataWin32.Trojan.PSE.15EXSUN
GoogleDetected
ALYacGen:Variant.Zusy.521164
MAXmalware (ai score=84)
VBA32BScope.Adware.123mania
Cylanceunsafe
RisingAdware.FlyStudio!1.6A5C (CLASSIC)
YandexTrojan.Strictor!yiGZfSYE2KY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Dropper-gen [Drp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Zusy.521164?

Zusy.521164 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment