Malware

Zusy.531714 (file analysis)

Malware Removal

The Zusy.531714 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.531714 virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Zusy.531714?


File Info:

name: 27CCA7019A9D2AEC9CA0.mlw
path: /opt/CAPEv2/storage/binaries/6d141e4dde99dcf872eb2aabd3337aa56539ed58d7686c40734e9aaca7ceced7
crc32: 7043A67E
md5: 27cca7019a9d2aec9ca008861bfc272d
sha1: aa3f48db84695bd8e7337d0955922cc77cc7ffc8
sha256: 6d141e4dde99dcf872eb2aabd3337aa56539ed58d7686c40734e9aaca7ceced7
sha512: c0e78113c42b123746ee997cea75e05271732ea068957115b275697b6da8820e44147a6bc9988732a51cecebb94fb3896aa2cab9ca37e3f044b2f248bef7e4aa
ssdeep: 6144:88gOPDnsA2/4Ze5qLUvDBhwNeACSyO1rKA4OA1K3KJ8nInnecZOljTHABWOm/m96:ZPglL5qLMDBhwUAoBzemOlfgBvm/mI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1DA056003AED3B017E4A341B5C666937875287F20F72892CB31C5F68A57F49D5983EA13
sha3_384: 1de9dbae1d900403cecbbe2c9686261a77ebf5562e73e1f6985e0660e2b19d57385c0ae297d93f3fc5bd4cdffab723d3
ep_bytes: e9ad320000e9d8310400e9135f0000e9
timestamp: 2023-12-28 06:26:02

Version Info:

0: [No Data]

Zusy.531714 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Shelm.1h!c
MicroWorld-eScanGen:Variant.Zusy.531714
SkyhighBehavesLike.Win32.Smokeloader.ct
McAfeeArtemis!27CCA7019A9D
Cylanceunsafe
SangforTrojan.Win32.Zusy.Vvml
BitDefenderThetaGen:NN.ZexaF.36680.ZCW@aqbMC0pj
SymantecML.Attribute.HighConfidence
KasperskyVHO:Trojan.Win32.Shelm.gen
BitDefenderGen:Variant.Zusy.531714
AvastWin32:MalwareX-gen [Trj]
SophosMal/Generic-S
VIPREGen:Variant.Zusy.531714
EmsisoftGen:Variant.Zusy.531714 (B)
GDataGen:Variant.Zusy.531714
Antiy-AVLTrojan/Win32.Shelm
ArcabitTrojan.Zusy.D81D02
ZoneAlarmVHO:Trojan.Win32.Shelm.gen
MicrosoftProgram:Win32/Wacapew.C!ml
GoogleDetected
AhnLab-V3Malware/Win.Generic.C5568235
MAXmalware (ai score=85)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R002H07A324
RisingTrojan.Generic@AI.100 (RDML:MmcEkZqvZYenNklOhWjfZA)
IkarusTrojan.SuspectCRC
FortinetMalicious_Behavior.SB
AVGWin32:MalwareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Zusy.531714?

Zusy.531714 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment