Malware

Zusy.297650 malicious file

Malware Removal

The Zusy.297650 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.297650 virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself

How to determine Zusy.297650?


File Info:

crc32: 70693CB2
md5: bdcb9946c685f08561ea45b37068e0b5
name: BDCB9946C685F08561EA45B37068E0B5.mlw
sha1: 890b777154849e26a527b2eb502b6f3ccb4129bb
sha256: 10648e7ab3e5623de3a63300fad53d594430e7ce37e51f626ef4edcec8de89ba
sha512: 6ce017d0a768287cf58195e83057f78091deb424e10f5c20a416470db5a88336079e4ad7499cca7cd4b8de64e6357992ff2dcbeb37aee87e0b004795d0dc2004
ssdeep: 24576:hxY3NtGUmJr+4Obxd+tPZSZyiE6EhE9xY3NtGUmJr+4Obxd+tPZSZAiE6EhE7:LY3buzMt0IY3buzMz0E
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.297650 also known as:

BkavW32.AIDetectVM.malware
K7AntiVirusTrojan-Downloader ( 0001b7311 )
DrWebTrojan.PWS.Gamania.10780
MicroWorld-eScanGen:Variant.Zusy.297650
ALYacGen:Variant.Zusy.297650
CylanceUnsafe
ZillyaTrojan.Banker.Win32.55
SangforMalware
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanSpy:Win32/Banker.e4b54340
K7GWTrojan-Downloader ( 0001b7311 )
Cybereasonmalicious.6c685f
TrendMicroTROJ_FAM_0000747.TOMA
CyrenW32/Trojan.ORSB-8183
SymantecTrojan.FakeAV
ESET-NOD32a variant of Win32/TrojanDownloader.FakeAlert.VA
ZonerTrojan.Win32.89386
APEXMalicious
TotalDefenseWin32/Oneraw.JJ
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Bancos-17785
GDataWin32.Trojan.FakeAV.Q
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.297650
NANO-AntivirusTrojan.Win32.Banker.oygn
ViRobotTrojan.Win32.Banker.766787
SUPERAntiSpywareTrojan.Agent/Gen-DownloaderBanload
TencentMalware.Win32.Gencirc.10b07a10
Ad-AwareGen:Variant.Zusy.297650
SophosMal/Banker-F
ComodoTrojWare.Win32.TrojanDownloader.Banload.~AHI@7lad3
F-SecureTrojan.TR/Delf.865208
BitDefenderThetaGen:NN.ZelphiF.34108.LHZ@ayJW84gO
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.th
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.bdcb9946c685f085
EmsisoftGen:Variant.Zusy.297650 (B)
SentinelOneDFI – Suspicious PE
F-ProtW32/Trojan2.JTRU
Endgamemalicious (high confidence)
WebrootW32.Trojan.Gen
AviraTR/Delf.865208
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan[Banker]/Win32.Banker
MicrosoftTrojanSpy:Win32/Banker.LY
JiangminTrojanSpy.Banker.rxi
ArcabitTrojan.Zusy.D48AB2
AegisLabTrojan.Win32.Generic.4!e
ZoneAlarmHEUR:Trojan.Win32.Generic
TACHYONBanker/W32.DP-Pharm.1663125
AhnLab-V3Trojan/Win32.Banker.R8976
Acronissuspicious
McAfeeFakeAV-DR
MAXmalware (ai score=86)
VBA32TrojanPSW.Gamania
MalwarebytesTrojan.Banker
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_FAM_0000747.TOMA
RisingDownloader.FakeAlert!8.4FF (CLOUD)
YandexTrojan.PWS.Banker!at4P5MVsOAQ
IkarusTrojan-Banker.Win32.Banker
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/FAKEAV.Q!tr
AVGWin32:Trojan-gen
Qihoo-360Generic/HEUR/QVM05.1.FD6C.Malware.Gen

How to remove Zusy.297650?

Zusy.297650 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment