Malware

Zusy.320976 removal instruction

Malware Removal

The Zusy.320976 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.320976 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup

How to determine Zusy.320976?


File Info:

crc32: 12C148CF
md5: ad5747435e9d819accbfa5653909bb89
name: AD5747435E9D819ACCBFA5653909BB89.mlw
sha1: 98a0875c233b3eb009ef6762578b2f0f02c7490e
sha256: a661065ffa3296e61b337a87977bfb1a817ec4069d9759adf1a5046caeba378c
sha512: ec647bc362ac7459b3072a5eedf5ff07f4572a500bec9d0fe914297e923aa84b1ea74ade186bef38a2f909c707cc1ca07d205d8adf5aba988c4cefbd883493ab
ssdeep: 3072:Bt87VnmZzJSmkP9PaayWdO0Yst6C+hqy5vlGBI/VcgL2czV0U+az:Btmn0zFZaFRYrC+7lKI/VcT0VO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.320976 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.320976
FireEyeGeneric.mg.ad5747435e9d819a
CAT-QuickHealTrojan.Cdzw
ALYacGen:Variant.Zusy.320976
CylanceUnsafe
AegisLabTrojan.Win32.Siscos.4!c
SangforMalware
K7AntiVirusTrojan ( 005328801 )
BitDefenderGen:Variant.Zusy.320976
K7GWTrojan ( 005328801 )
Cybereasonmalicious.c233b3
BitDefenderThetaGen:NN.ZexaF.34688.qqW@aSQB2ykb
CyrenW32/Trojan.IAUF-5154
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.EFEV
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Siscos.gen
AlibabaTrojan:Win32/GenKryptik.055ac2de
ViRobotTrojan.Win32.Z.Zusy.266240.FL
RisingTrojan.Generic@ML.97 (RDMK:9wUu6fXNCJ/qFR4xT6VDVg)
Ad-AwareGen:Variant.Zusy.320976
EmsisoftGen:Variant.Zusy.320976 (B)
ComodoMalware@#3bwzkqk3z8f8y
F-SecureHeuristic.HEUR/AGEN.1106015
DrWebTrojan.DownLoader36.9351
TrendMicroTROJ_GEN.R002C0PLC20
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SophosMal/Generic-S
IkarusAdWare.Win32.BlackMoon
AviraHEUR/AGEN.1106015
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.GenKryptik
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AAA6
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Zusy.D4E5D0
AhnLab-V3Trojan/Win32.Kryptik.C4247072
ZoneAlarmHEUR:Trojan.Win32.Siscos.gen
GDataGen:Variant.Zusy.320976
CynetMalicious (score: 100)
TotalDefenseWin32/Oflwr.A!crypt
McAfeeGenericRXMS-PR!AD5747435E9D
VBA32BScope.Trojan.Siscos
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0PLC20
TencentMalware.Win32.Gencirc.11b0df5a
SentinelOneStatic AI – Suspicious PE
FortinetRiskware/Siscos
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.e48

How to remove Zusy.320976?

Zusy.320976 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment