Malware

Zusy.289617 (file analysis)

Malware Removal

The Zusy.289617 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.289617 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz

How to determine Zusy.289617?


File Info:

crc32: 7689AC84
md5: b63c6ffc4f3926518e4904b6f00022be
name: ll773o.exe
sha1: 054a1a6ac5cd3a616935ba783456cfc95a65652c
sha256: c2a2f6526b9f10d7af36254007a0eb4b222db8ece07dc887dbbb2124f6d39692
sha512: 6b52986e5af5488a13c262e995bcfac860209f9e809c23ed64c5330ba05ef4a1592abc032586645044015590902d0c5ee9d533c089694d608e5d8a7c52423cf6
ssdeep: 12288:CqGw1T2nYgCnLMfwcd5R6XgaEX0V/R8lnLvDbbDZM+eotreVySjA5UL9E:CqGY+CLwXR6KIUnXDS+eotrGjL9E
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0804 0x04b0
InternalName: QQ
FileVersion: 1.00
CompanyName: China
ProductName: x5de5x7a0b1
ProductVersion: 1.00
OriginalFilename: QQ.exe

Zusy.289617 also known as:

BkavHW32.Packed.
MicroWorld-eScanGen:Variant.Zusy.289617
FireEyeGeneric.mg.b63c6ffc4f392651
McAfeeGeneric-FAAF!B63C6FFC4F39
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Zusy.289617
K7GWTrojan ( 00006f8a1 )
Invinceaheuristic
BitDefenderThetaAI:Packer.070809441F
APEXMalicious
AvastWin32:Trojan-gen
GDataGen:Variant.Zusy.289617
KasperskyHEUR:Trojan.Win32.Generic
AlibabaVirTool:Win32/Obfuscator.d383c96f
AegisLabTrojan.Win32.Generic.4!c
TencentTrojan.Win32.FakeApp.b
Endgamemalicious (high confidence)
SophosMal/VMProtBad-A
F-SecureTrojan.TR/Black.Gen2
BaiduWin32.Trojan.KryptikV.g
TrendMicroTROJ_GEN.R002C0CCH20
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zusy.289617 (B)
IkarusVirTool.Win32.Obfuscator
AviraTR/Black.Gen2
WebrootW32.Malware.gen
MAXmalware (ai score=80)
ArcabitTrojan.Zusy.D46B51
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftVirTool:Win32/Obfuscator.XZ
AhnLab-V3Trojan/Win32.Strictor.C916130
Acronissuspicious
ALYacGen:Variant.Zusy.289617
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Packed.VMProtect.AAH
TrendMicro-HouseCallTROJ_GEN.R002C0CCH20
RisingTrojan.Generic!8.C3 (CLOUD)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Generic.A!tr
Ad-AwareGen:Variant.Zusy.289617
AVGWin32:Trojan-gen
Cybereasonmalicious.c4f392
Paloaltogeneric.ml

How to remove Zusy.289617?

Zusy.289617 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment