Malware

What is “Zusy.395142”?

Malware Removal

The Zusy.395142 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.395142 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Detects Avast Antivirus through the presence of a library
  • Network activity detected but not expressed in API logs

How to determine Zusy.395142?


File Info:

crc32: 84556963
md5: 4663137b64e577df30a6367dec6be9cb
name: 4663137B64E577DF30A6367DEC6BE9CB.mlw
sha1: 3352b3b68a113deda774170a9c29cae3defdc166
sha256: c2e3a2d1abfc4020079e1b755a99595687cd15cb86a3edbccd718e495e082959
sha512: 7cbed3397abc7c115ee3395b310a8d32d30766094a70e9d7fbe7afe52270bf561f6f8d5e348e16c9d3cf8c3ba15f533300d7f9238351b00b7b14f9124941b0ae
ssdeep: 24576:YO6GzQSVzzwFic3RcEBe+EcPhJqBPubfajgnB7uN4ZIXuW41o+H:nDzQ+zzwlhrB9EIOMB7JZXW4S+H
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.395142 also known as:

K7AntiVirusTrojan ( 00581f561 )
LionicTrojan.Win32.Hesv.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.395142
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojan:Win32/FakeAlert.10eeecdd
K7GWTrojan ( 00581f561 )
Cybereasonmalicious.68a113
CyrenW32/FakeFolder.S.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.ADBW
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Hesv.gen
BitDefenderGen:Variant.Zusy.395142
NANO-AntivirusTrojan.Win32.Hesv.iynouc
MicroWorld-eScanGen:Variant.Zusy.395142
TencentMalware.Win32.Gencirc.10ce7e10
Ad-AwareGen:Variant.Zusy.395142
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34170.pvW@aWgT9Lii
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PG321
McAfee-GW-EditionGenericRXOW-RQ!4663137B64E5
FireEyeGeneric.mg.4663137b64e577df
EmsisoftGen:Variant.Zusy.395142 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Agent.qhxyj
eGambitUnsafe.AI_Score_92%
Antiy-AVLTrojan/Generic.ASMalwS.348A97F
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.Win32.Hesv.gen
GDataGen:Variant.Zusy.395142
AhnLab-V3Dropper/Win32.Agent.C1956471
McAfeeGenericRXOW-RQ!4663137B64E5
MAXmalware (ai score=83)
VBA32BScope.Trojan.Hesv
MalwarebytesMalware.AI.3071856360
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0PG321
RisingMalware.FakeFolder/ICON!1.6AA9 (CLASSIC)
YandexTrojan.Hesv!2dqMvGv2Mgg
IkarusTrojan.Win32.Agent
FortinetW32/Agent.ADBW!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Zusy.395142?

Zusy.395142 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment