Malware

How to remove “Zusy.391468”?

Malware Removal

The Zusy.391468 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.391468 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Starts servers listening on 127.0.0.1:0
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Serbian
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.391468?


File Info:

crc32: CAA10A74
md5: be867e17fdd1e06aee11c22c83c2e384
name: BE867E17FDD1E06AEE11C22C83C2E384.mlw
sha1: c69be3b2a781a3cd1e6e4712b69131a293f6d7fa
sha256: c144b9c8ba25c23f058ddcae2adb58f474c1e7c660c91d0417d1ec57a8029e8c
sha512: 506faff34da08b853c28e91e71287091e9c835845944e2df41ed4bce5107c8443a4bdc6302895cc03351ea9715584f0dfc17641d935afcc4680d3ce59263c3cb
ssdeep: 6144:0D7KCLg8+eC+9hWE54UTU29neqxf0t6nBnmm8HK82A6fmHmGI:87KCsAzQUT3N04nBmL2A6fcx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: Variant of fucks
FileVersion: 6.36.43
Copyright: Copyrighz (C) 2020, wodkagudy
ProductVersion: 1.14.44
Translation: 0x0273 0x011d

Zusy.391468 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0056689f1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:Win32/GandCrab.7c0c0e25
K7GWTrojan ( 0056689f1 )
Cybereasonmalicious.2a781a
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.HLPN
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Zusy.391468
MicroWorld-eScanGen:Variant.Zusy.391468
Ad-AwareGen:Variant.Zusy.391468
McAfee-GW-EditionBehavesLike.Win32.Virut.gc
FireEyeGeneric.mg.be867e17fdd1e06a
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
MicrosoftTrojan:Win32/Azorult.OG!MTB
GDataGen:Variant.Zusy.391468
AhnLab-V3Malware/Win.AGEN.C4542884
Acronissuspicious
McAfeeRDN/Generic.hbg
MAXmalware (ai score=82)
MalwarebytesTrojan.MalPack.GS
TrendMicro-HouseCallTROJ_GEN.R06CH07G521
RisingTrojan.Kryptik!1.D7D4 (CLASSIC)
IkarusTrojan.Win32.Glupteba
FortinetW32/GenKryptik.ERHN!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HwoCYkAA

How to remove Zusy.391468?

Zusy.391468 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment