Malware

How to remove “Zusy.246371”?

Malware Removal

The Zusy.246371 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.246371 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs
  • Attempts to interact with an Alternate Data Stream (ADS)

How to determine Zusy.246371?


File Info:

crc32: EEE626A5
md5: 8813814eee80d2d3ecb405120c76b2a5
name: 8813814EEE80D2D3ECB405120C76B2A5.mlw
sha1: 47d76c94501f7522c01031c9850666c98dc6af67
sha256: 6497d8e0e238eb414aa12ff036d028b82f55110046c0591ecff755093d093f8f
sha512: d259a13d587a165cc4e03ab7fbdb4fd0c81079b90e9b1e334f3d73abe5c3b25a339e8e208e0d9d8525f795850d72c0cca939dbb7510fa67083ded763e10b2968
ssdeep: 6144:nleIaxFhe7ga9nHHVtu7Ifo49bUecnntz1spJ9YJUUJERvxeXYLIV9O:kThW9LZUeStBs/9YJUUSvxra9O
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2017
Assembly Version: 1.0.0.0
InternalName: Windows.exe
FileVersion: 1.0.0.0
ProductName: Windows
ProductVersion: 1.0.0.0
FileDescription: Windows
OriginalFilename: Windows.exe

Zusy.246371 also known as:

LionicTrojan.MSIL.Disfa.4!c
Elasticmalicious (high confidence)
ALYacGen:Variant.Zusy.246371
CylanceUnsafe
ZillyaTrojan.Disfa.Win32.67019
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:MSIL/Disfa.3f10a0b9
K7GWTrojan ( 005224d51 )
K7AntiVirusTrojan ( 005224d51 )
CyrenW32/S-3199db3a!Eldorado
ESET-NOD32a variant of Generik.KCFQWFZ
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyTrojan.MSIL.Disfa.mjhf
BitDefenderGen:Variant.Zusy.246371
NANO-AntivirusTrojan.Win32.Disfa.euvwho
MicroWorld-eScanGen:Variant.Zusy.246371
TencentMsil.Trojan.Disfa.Dyzr
Ad-AwareGen:Variant.Zusy.246371
SophosML/PE-A + Troj/MSIL-JWI
BitDefenderThetaGen:NN.ZemsilF.34236.vq0@aqehiCb
VIPRETrojan.Win32.Generic!BT
EmsisoftGen:Variant.Zusy.246371 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.hkgp
AviraHEUR/AGEN.1128489
MicrosoftBackdoor:MSIL/Bladabindi
ArcabitTrojan.Zusy.D3C263
ZoneAlarmTrojan.MSIL.Disfa.mjhf
AhnLab-V3Trojan/Win32.Bladabindi.C2317003
McAfeePacked-SD!8813814EEE80
MAXmalware (ai score=100)
VBA32Trojan.MSIL.Disfa
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
YandexTrojan.Disfa!iu209iM3lqY
IkarusTrojan.SuspectCRC
FortinetMSIL/Kryptik.MQN!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Zusy.246371?

Zusy.246371 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment