Malware

Zusy.536314 (file analysis)

Malware Removal

The Zusy.536314 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.536314 virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Zusy.536314?


File Info:

name: 273CD2D4F03438AE186B.mlw
path: /opt/CAPEv2/storage/binaries/2b60da78a995e7a67d37a8306c347ecd73b84445de070bf7a8134b0c5b792032
crc32: 2CCA3DA0
md5: 273cd2d4f03438ae186b5e2ceb6c5f26
sha1: 570cdfa6f9940884f76467adac0290b2f45f03dc
sha256: 2b60da78a995e7a67d37a8306c347ecd73b84445de070bf7a8134b0c5b792032
sha512: 7571bee6d491e23792a65571d9b8aa52e562a866dcd80e0fc3f2e70182d902fd158463b7bf515f9a791745cc8f2b070f85f9a58c4ba9374eebab8c96266f6526
ssdeep: 192:tsOTXSNYR/HAhghnpwaSHER1LlNOiT/NSJH:tLXSNS/HAInpwaSgTT/8H
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T11712F81ABBF88725D4AE0F3AE4A353610535F2655D53D74F1C8A700F9C517A80962FF2
sha3_384: aa0ad6e341f9d5ba26585bbba2b595290a645e0b3e5fbf5f0179cb42678aca4e6b5ef77f0fe0598f11b757ee69e69a25
ep_bytes: ff250020001000000000000000000000
timestamp: 2086-07-27 17:34:55

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: WingsOfGod
FileVersion: 1.0.0.0
InternalName: WingsOfGod.dll
LegalCopyright: Copyright © 2023
LegalTrademarks:
OriginalFilename: WingsOfGod.dll
ProductName: WingsOfGod
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Zusy.536314 also known as:

BkavW32.AIDetectMalware.CS
Elasticmalicious (high confidence)
ALYacGen:Variant.Zusy.536314
Cylanceunsafe
VIPREGen:Variant.Zusy.536314
SangforTrojan.Win32.Zusy.Vx6q
BitDefenderGen:Variant.Zusy.536314
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Zusy.D82EFA
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Agent.EKF
AlibabaTrojan:MSIL/BackdoorX.0b8b482b
MicroWorld-eScanGen:Variant.Zusy.536314
AvastWin32:BackdoorX-gen [Trj]
FireEyeGen:Variant.Zusy.536314
EmsisoftGen:Variant.Zusy.536314 (B)
GDataGen:Variant.Zusy.536314
AhnLab-V3Backdoor/Win.WogRAT.C5593109
McAfeeArtemis!273CD2D4F034
MAXmalware (ai score=85)
AVGWin32:BackdoorX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Zusy.536314?

Zusy.536314 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment