Malware

Should I remove “Zusy.394472”?

Malware Removal

The Zusy.394472 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.394472 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Zusy.394472?


File Info:

crc32: EB9E44FC
md5: 54c6e68d889239ef978e4221f8add60f
name: 54C6E68D889239EF978E4221F8ADD60F.mlw
sha1: 500f8852aa4cf26eb57d544fa3017bbab75aafce
sha256: 71cb97b67ebcc50a0bef217b3ca9591cfa49f6b8c8d11ee9952c2cde0b7b6a51
sha512: 09d0bc694eababc0de157884383fff81c07b5c576bfcbfdf763b41b8a96a845b4fc29b04ccd0b82e70de085696f86afd79b94f2be210b545e0a91d0ffd793a7e
ssdeep: 3072:rrJfUq2HOAp1sll7rzhuwXGI3AJwC1ZGLt+5zsZ/bcm/tDhxABxVr6XBMf8n:rtct8xrEwWXwzLtHZ/byBxo9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.394472 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Noon.l!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen14.45102
CynetMalicious (score: 100)
ALYacGen:Variant.Ulise.260719
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.2aa4cf
CyrenW32/Trojan.JUYE-7820
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EPUF
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyTrojan-Spy.Win32.Noon.bbji
BitDefenderGen:Variant.Zusy.394472
MicroWorld-eScanGen:Variant.Zusy.394472
TencentWin32.Trojan-spy.Noon.Swuw
Ad-AwareGen:Variant.Zusy.394472
SophosMal/Generic-S
ComodoTrojWare.Win32.Agent.mdspy@0
BitDefenderThetaGen:NN.ZexaF.34050.miZ@ai0WSjh
McAfee-GW-EditionBehavesLike.Win32.VirRansom.cc
FireEyeGeneric.mg.54c6e68d889239ef
EmsisoftGen:Variant.Zusy.394472 (B)
SentinelOneStatic AI – Suspicious PE
KingsoftWin32.Troj.Noon.bb.(kcloud)
MicrosoftTrojan:Win32/VirRansom.DM!MTB
ArcabitTrojan.Ulise.D3FA6F
GDataGen:Variant.Zusy.394472
AhnLab-V3Trojan/Win.Generic.R432992
McAfeeArtemis!54C6E68D8892
MAXmalware (ai score=89)
VBA32BScope.Trojan-Dropper.Injector
TrendMicro-HouseCallTROJ_FRS.0NA103GL21
RisingTrojan.Generic@ML.94 (RDML:D5mWenjhSovR5rKDUoZnPQ)
IkarusTrojan.Win32.Injector
FortinetW32/GenKryptik.AYEB!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360HEUR/QVM20.1.BCBF.Malware.Gen

How to remove Zusy.394472?

Zusy.394472 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment