Malware

Zusy.389103 removal tips

Malware Removal

The Zusy.389103 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.389103 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
samegresites.live

How to determine Zusy.389103?


File Info:

crc32: 1A033587
md5: f6f29588f6b0c628ff9048da2e0828d4
name: F6F29588F6B0C628FF9048DA2E0828D4.mlw
sha1: 28ad6f2f48d35c5dafedcc2daa67100d5cd12c32
sha256: ccd8253790dac3544102963a6fd0eec5ae0df4d7fb6647d05198d4fe6ab721a4
sha512: 6aabc9cc28a45dd50ddc747ceaaf2062a4adecd14eb595b1eda8340de0d0c584475952746b36d0a5073ba1e371d3223801166cab5d97e4ae243c344a41c01c89
ssdeep: 24576:1Ujio4MoumhNTJfKMosHA953EKq7iRzalN6Hk/8LGVJ5immy:yz4MerKM55xeYikUlJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: Duplicator
FileVersion: 1.5.0.0
CompanyName: HiKi-Soft
LegalTrademarks: HiKi
Comments: https://hiki-soft.ru
ProductName: Duplicate finder and remover HiKi
ProductVersion: 1.5
FileDescription: Duplicate finder and remover HiKi
OriginalFilename: double.exe
Translation: 0x0409 0x04e4

Zusy.389103 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0058214e1 )
LionicTrojan.Win32.Bingoml.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.389103
ALYacGen:Variant.Zusy.389103
CylanceUnsafe
ZillyaTrojan.Bingoml.Win32.4865
SangforTrojan.Win32.Bingoml.gen
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojan:Win32/Bingoml.f7fb297e
K7GWTrojan ( 0058214e1 )
Cybereasonmalicious.f48d35
CyrenW32/Sabsik.F.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLIQ
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
KasperskyHEUR:Trojan.Win32.Bingoml.gen
BitDefenderGen:Variant.Zusy.389103
TencentWin32.Trojan.Bingoml.Egec
Ad-AwareGen:Variant.Zusy.389103
BitDefenderThetaGen:NN.ZexaF.34266.ND0@aSWoq7ai
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PGD21
FireEyeGeneric.mg.f6f29588f6b0c628
EmsisoftGen:Variant.Zusy.389103 (B)
JiangminTrojan.Bingoml.als
AviraHEUR/AGEN.1143574
Antiy-AVLTrojan/Generic.ASMalwS.3432E1F
MicrosoftTrojan:Win32/Tnega!ml
GDataWin32.Trojan.PSE.1DTPNY9
AhnLab-V3Adware/Win.Generic.R425898
McAfeeGenericRXQC-BH!F6F29588F6B0
MAXmalware (ai score=87)
VBA32Trojan.Bingoml
MalwarebytesAdware.RussAd
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0PGD21
RisingTrojan.Kryptik!1.AA55 (CLASSIC)
YandexTrojan.Bingoml!Ecy6Ld82NRA
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HLMN!tr
AVGWin32:AdwareX-gen [Adw]
Paloaltogeneric.ml

How to remove Zusy.389103?

Zusy.389103 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment