Malware

About “Zusy.340072” infection

Malware Removal

The Zusy.340072 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.340072 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Zusy.340072?


File Info:

crc32: F48922B2
md5: cc1f7b72e9d2130b5cbada0b931efbe0
name: CC1F7B72E9D2130B5CBADA0B931EFBE0.mlw
sha1: 39daa3502cce054a93f5939f1744cfe3d87e611a
sha256: 727a720f0ed8942d28c1cf7e7185f868706dcd2693f2868e6b5932f382020a39
sha512: ae324bf2ca5c8ae7ba7fedf733837726186cede622e49901bad65f2eb4fcc545029a1b15206946c94f5908edb3ab6e642d18065adbfec29c2f5941eb5a578af2
ssdeep: 24576:Wf93xuO8qn7G88Ze1HYcddMaCyQJynnBJHPAj9KUoOYzIo9ULq3:WtI/Ii9aRdSJcf4hKUoOY0uULq3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Co90b324p.
InternalName:
FileVersion: 59845t6
CompanyName: vytrtr
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 817656
FileDescription:
OriginalFilename:
Translation: 0x0409 0x04e4

Zusy.340072 also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Zusy.340072
FireEyeGeneric.mg.cc1f7b72e9d2130b
CAT-QuickHealTrojan.DriveHide.VN8
ALYacGen:Variant.Zusy.340072
SangforMalware
BitDefenderGen:Variant.Zusy.340072
BitDefenderThetaAI:Packer.5AEBB01121
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Dropper.Undefined-6663182-0
Ad-AwareGen:Variant.Zusy.340072
SophosTroj/Agent-AJFK
DrWebBackDoor.SpyBotNET.25
InvinceaML/PE-A + Troj/Agent-AJFK
McAfee-GW-EditionBehavesLike.Win32.Fareit.tc
EmsisoftGen:Variant.Zusy.340072 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Kryptik.cvu
MAXmalware (ai score=80)
MicrosoftPWS:Win32/Fareit!ml
ArcabitTrojan.Zusy.D53068
GDataWin32.Trojan.PSE.1QAU741
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Injector.R354305
McAfeeFareit-FZN!CC1F7B72E9D2
VBA32TScope.Trojan.Delf
MalwarebytesTrojan.MalPack.DLF
ESET-NOD32a variant of Win32/GenKryptik.EWDK
RisingTrojan.Injector!1.CEB9 (CLASSIC)
IkarusTrojan.Inject
eGambitUnsafe.AI_Score_82%
FortinetW32/Injector.ENSD!tr
AVGWin32:PWSX-gen [Trj]
Cybereasonmalicious.2e9d21
AvastWin32:PWSX-gen [Trj]

How to remove Zusy.340072?

Zusy.340072 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment