Malware

About “Zusy.328564 (B)” infection

Malware Removal

The Zusy.328564 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.328564 (B) virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Attempts to identify installed AV products by installation directory
  • Anomalous binary characteristics

How to determine Zusy.328564 (B)?


File Info:

crc32: 854600B6
md5: ecd2dab44b7713d03a3511784c5c94e1
name: ECD2DAB44B7713D03A3511784C5C94E1.mlw
sha1: ad0c1319ac20d696f60e968e9548deb7c08badf4
sha256: 406a5b73c768d019808c2a779729b47d181fec402073f58ab07afc9630904198
sha512: 73f166a6bf85ed4e68c0d6aceea92954e843746a301724097707e2cdbd015d9397426bfcf3eb610bacf2a5de14fbf9b34fe9eabe430fa01aaa72bd0995db2518
ssdeep: 6144:4b3XpbomoGOuC/54CpXclGF48APbnkgg8Ryhc7gbQSXNmtFFw:G3XSmvRo0KGDnPQhMcUtzw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.328564 (B) also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004c61ee1 )
LionicTrojan.Win32.Kovter.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Kovter.297
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.328564
CylanceUnsafe
ZillyaTrojan.Kovter.Win32.2611
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Kovter.2dc861ae
K7GWTrojan ( 004c61ee1 )
Cybereasonmalicious.44b771
CyrenW32/S-a26307b3!Eldorado
SymantecRansom.Kovter
ESET-NOD32Win32/Kovter.D
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Malware.Kovter-2379
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.328564
NANO-AntivirusTrojan.Win32.Kovter.ezhjke
MicroWorld-eScanGen:Variant.Zusy.328564
TencentMalware.Win32.Gencirc.10b6c47e
Ad-AwareGen:Variant.Zusy.328564
SophosMal/Generic-R + Troj/Kovter-FI
BitDefenderThetaGen:NN.ZexaF.34790.vqX@aGvANVb
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_KOVTER.YAEC
McAfee-GW-EditionTrojan-FJZM!ECD2DAB44B77
FireEyeGeneric.mg.ecd2dab44b7713d0
EmsisoftGen:Variant.Zusy.328564 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Kovter.bdm
WebrootW32.Trojan.Ransom
AviraHEUR/AGEN.1124205
Antiy-AVLTrojan/Generic.ASMalwS.1BE126A
KingsoftWin32.Troj.Kovter.t.(kcloud)
MicrosoftTrojan:Win32/Dorv.D!rfn
ArcabitTrojan.Zusy.D50374
GDataGen:Variant.Zusy.328564
AhnLab-V3Trojan/Win32.Miuref.R189097
Acronissuspicious
McAfeeTrojan-FJZM!ECD2DAB44B77
MAXmalware (ai score=100)
VBA32Trojan.Kovter
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_KOVTER.YAEC
RisingTrojan.Generic@ML.98 (RDML:pJ7uyxTQ4MPtzcHRiNuLUA)
IkarusTrojan.Win32.Kovter
FortinetW32/Kryptik.FJGA!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HwgAEpsA

How to remove Zusy.328564 (B)?

Zusy.328564 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment