Malware

About “Zusy.329390” infection

Malware Removal

The Zusy.329390 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.329390 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Looks up the external IP address
  • Executed a process and injected code into it, probably while unpacking
  • Behavior consistent with a dropper attempting to download the next stage.
  • A process sent information about the computer to a remote location.

Related domains:

api.ipify.org
eventlarva.com
necemblem.ru
systemperal.ru

How to determine Zusy.329390?


File Info:

crc32: ED57325F
md5: 3d7b5db76ef8ba51d0a5ac8558fccde3
name: 3D7B5DB76EF8BA51D0A5AC8558FCCDE3.mlw
sha1: 8fb312ab195e471f6a5b7d682d37e20a41bbd4b4
sha256: dd7d008bf1ed8b1bea6cf80588c15ca6f1ab1da629338abfdc06258551de8366
sha512: 9dbbae95365a7f8b3774800e403188643b07f4ae5f746daa3aa95508eb36bc74f8016b9f0a5f8bcd05dab629153254b5f008f7c614acb0dbc06c47d8efe6e46c
ssdeep: 12288:yOeKvWSp3xrAwMtIcmRrXt6SVbH5PcozzaPcfzL+WvpxvWGvZldz+SNldGqIvvaw:yOeKvWSp3xrAwMtIcmRrXt6SVbH5Pcoa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.329390 also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Zusy.329390
FireEyeGeneric.mg.3d7b5db76ef8ba51
CAT-QuickHealTrojan.Hancitor
ALYacGen:Variant.Zusy.329390
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 005722431 )
BitDefenderGen:Variant.Zusy.329390
K7GWTrojan ( 005722431 )
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:RATX-gen [Trj]
KasperskyTrojan.Win32.Hancitor.eq
RisingMalware.Obscure/Heur!1.A89E (CLASSIC)
Ad-AwareGen:Variant.Zusy.329390
EmsisoftGen:Variant.Zusy.329390 (B)
DrWebTrojan.Chanitor.59
McAfee-GW-EditionGenericRXMN-YH!3D7B5DB76EF8
MaxSecureTrojan.Malware.300983.susgen
JiangminTrojanDownloader.Geral.egp
MAXmalware (ai score=81)
MicrosoftTrojan:Win32/Wacatac.C!ml
ArcabitTrojan.Zusy.D506AE
ZoneAlarmTrojan.Win32.Hancitor.eq
GDataGen:Variant.Zusy.329390
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Reputation.C4223843
McAfeeGenericRXMN-YH!3D7B5DB76EF8
VBA32BScope.TrojanDownloader.Geral
MalwarebytesTrojan.MalPack.PD
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.FQEV
YandexTrojan.Hancitor!s8ix3dW9740
eGambitUnsafe.AI_Score_99%
AVGWin32:RATX-gen [Trj]
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Zusy.329390?

Zusy.329390 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment