Malware

Zusy.540971 removal tips

Malware Removal

The Zusy.540971 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.540971 virus can do?

  • Uses Windows utilities for basic functionality
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Zusy.540971?


File Info:

name: 41374E5D4178D817B16B.mlw
path: /opt/CAPEv2/storage/binaries/c0fe543e692723f22ede4e3b2e354d01f974591877af078c26ae6755ac945867
crc32: AAA69A0A
md5: 41374e5d4178d817b16b1d97c5df3224
sha1: 4f661ae128b61d4eb573bb7511a4a1560d815925
sha256: c0fe543e692723f22ede4e3b2e354d01f974591877af078c26ae6755ac945867
sha512: 9b57c933a6e2986738db9c46dcfaebd46a97d49e4a4ad9b8044d0f421845c0e8b11105a8824214c0024f73c2515ac3fb90ce7242abd1e494a0c491692aa1ecc6
ssdeep: 1536:27M3BhP/E9y9f/zMdv/4P6bR1ik5J/lEuU0Ay2s+eHxCEtkz30rtr3:j3BN+IfGO6bRnlZAvHcxCEtg30Br
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T169A37C13B8D1C0B2F516017959AADA7357377A050F78D9C37798CA8EBA623D04AB7EC0
sha3_384: 37cda267db49ef427fa5c67032022bb6ff7961a91dd501611027ddcbaf516b44f486c6eef59681ce262f2c2762e2c690
ep_bytes: e875510000e916feffff8b442404a328
timestamp: 2013-04-02 06:46:11

Version Info:

0: [No Data]

Zusy.540971 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Shyape.7!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.540971
FireEyeGeneric.mg.41374e5d4178d817
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.PWSZbot.cm
ALYacGen:Variant.Zusy.540971
Cylanceunsafe
ZillyaTrojan.Shyape.Win32.2079
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0054e5911 )
AlibabaTrojanBanker:Win32/Sakurel.81955fde
K7GWTrojan ( 0054e5911 )
BitDefenderThetaAI:Packer.CE300FC220
VirITTrojan.Win32.DownLoad3.BIXU
SymantecTrojan.Sakurel
ESET-NOD32a variant of Win32/Shyape.G
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0CD124
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Malware.Scar-6745903-0
KasperskyHEUR:Trojan-Banker.Win32.BlueShai.gen
BitDefenderGen:Variant.Zusy.540971
NANO-AntivirusTrojan.Win64.Agent.cysfdn
TencentTrojan-Banker.Win32.BlueShai.ha
EmsisoftGen:Variant.Zusy.540971 (B)
BaiduWin32.Trojan.Shyape.a
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.DownLoader46.49440
VIPREGen:Variant.Zusy.540971
TrendMicroTROJ_GEN.R002C0CD124
Trapminemalicious.high.ml.score
SophosMal/Generic-S
Paloaltogeneric.ml
MAXmalware (ai score=100)
JiangminTrojan.Banker.BlueShai.q
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/Agent.EVEA-1512
Antiy-AVLTrojan/Win32.Shyape
KingsoftWin32.Trojan-Banker.BlueShai.gen
MicrosoftTrojan:Win32/Sakurel.B!dha
XcitiumTrojWare.Win32.Shyape.GA@590rbc
ArcabitTrojan.Zusy.D8412B
ViRobotTrojan.Win.Z.Shyape.102400.C
ZoneAlarmHEUR:Trojan-Banker.Win32.BlueShai.gen
GDataWin32.Trojan.Sakurel.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Scar.R160937
Acronissuspicious
McAfeeGenericR-GLN!41374E5D4178
VBA32BScope.Trojan.Scar
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
RisingBackdoor.FFRat!1.A74F (CLASSIC)
YandexTrojan.GenAsa!mcUF4auL+so
IkarusTrojan.Win32.Scar
MaxSecureTrojan.Malware.11717402.susgen
FortinetW32/Shyape.G!tr
AVGWin32:DropperX-gen [Drp]
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Shyape

How to remove Zusy.540971?

Zusy.540971 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment