Malware

What is “Zusy.110696”?

Malware Removal

The Zusy.110696 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.110696 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to delete volume shadow copies
  • A system process is generating network traffic likely as a result of process injection
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Zusy.110696?


File Info:

crc32: EB367708
md5: 6fb99593905840cf95ab2364c4c87d63
name: 6FB99593905840CF95AB2364C4C87D63.mlw
sha1: 8d0aafee1cabe7b6cc0caf93ffafd3da3bff8b9b
sha256: c9b0c5e1e5f11319e9b8845cf27106dd31254077caec4b9bb3ae16f8ac5420c7
sha512: ed5da6f84c3627b740a153db5a86facf23710bfd2f83aafbfe8fc64098823cfec27909cbcf9d80d0ae17c32d928e5dc91a8481973c2ec22436e6e30bd9d32a5d
ssdeep: 6144:8joxeLzWAedqagVnGxqFL9hCPFvuE/pvj3hGUdXZGKb1T7oPFkCs1QBPY4:VxeHWAIMicCR/FHXZtSj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2006-2010 Google Inc. All Rights Reserved.
InternalName: chrome_exe
CompanyShortName: Google
FileVersion: 20.0.1132.47
CompanyName: Google Inc.
ProductShortName: Chrome
ProductName: Google Chrome
LastChange: 144678
ProductVersion: 20.0.1132.47
FileDescription: Google Chrome
OriginalFilename: chrome.exe
Official Build: 1
Translation: 0x0409 0x04b0

Zusy.110696 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004af2511 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.761
CynetMalicious (score: 100)
CAT-QuickHealTrojanPWS.Zbot.ZA4
ALYacGen:Variant.Zusy.110696
CylanceUnsafe
ZillyaTrojan.Crypren.Win32.79
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaRansom:Win32/Teerac.3b342eb3
K7GWTrojan ( 004af2511 )
Cybereasonmalicious.390584
CyrenW32/Injector.CB.gen!Eldorado
SymantecRansom.TorrentLocker
ESET-NOD32Win32/Filecoder.TorrentLocker.A
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Rack.ab
BitDefenderGen:Variant.Zusy.110696
NANO-AntivirusTrojan.Win32.Filecoder.dgqytf
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
MicroWorld-eScanGen:Variant.Zusy.110696
TencentWin32.Trojan.Raas.Auto
Ad-AwareGen:Variant.Zusy.110696
SophosML/PE-A + Mal/Wonton-S
ComodoTrojWare.Win32.Spy.Zbot.BMT@5hj2c0
BitDefenderThetaGen:NN.ZexaF.34670.Bq0@aGMHExmi
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_CRYPLOCK.N
McAfee-GW-EditionPWSZbot-FAFA!6FB995939058
FireEyeGeneric.mg.6fb99593905840cf
EmsisoftGen:Variant.Zusy.110696 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Cryptolocker.a
WebrootW32.Torrent.Locker
AviraHEUR/AGEN.1102753
eGambitGeneric.Dropper
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Teerac.A
ZoneAlarmTrojan-Ransom.Win32.Rack.ab
GDataGen:Variant.Zusy.110696
TACHYONTrojan/W32.Rack.452608
AhnLab-V3Trojan/Win32.Crilock.R124103
McAfeePWSZbot-FAFA!6FB995939058
MAXmalware (ai score=100)
VBA32Trojan.Scarsi
MalwarebytesTrojan.Agent.FG
PandaTrj/Crypter.B
TrendMicro-HouseCallTROJ_CRYPLOCK.N
RisingRansom.Rack!8.2ED (CLOUD)
YandexTrojan.Filecoder!AFeL7Umrf7U
IkarusTrojan-Ransom.CryptoLocker
MaxSecureTrojan.Malware.7874834.susgen
FortinetW32/Injector.MMTR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.TorrentLocker.HwoCEpsA

How to remove Zusy.110696?

Zusy.110696 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment