Malware

About “Zusy.396065” infection

Malware Removal

The Zusy.396065 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.396065 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
jatkit.ga

How to determine Zusy.396065?


File Info:

crc32: 766B64FE
md5: 305bd8bfcb312b449b4159aa49ab5512
name: 305BD8BFCB312B449B4159AA49AB5512.mlw
sha1: b2303e3b96b4b06b32532d4d492b99215926850e
sha256: 8f62ec2e29007cbcd6a9ff4733bdda13170c4f4737076190537b4a6a2cfe8f87
sha512: 32b09f9d7fda0260a9eed487045ec867f2f8e2ddf2fbc59ab57ec96fcacf9f05b215627b211428a871f460e694d4da9c99cdd0db6a349f97e0b89ca7b09557aa
ssdeep: 12288:F9A6tdc+Vni0zauPsH+gAsIM+IF2c4mGI1hcITH7wWjX7jl8DBPCE+V0GdQi3/d:FXLni0hI6wf7T7L2BPC3P+i3/d
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.396065 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005469fb1 )
LionicTrojan.Win32.Noon.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.9675
CynetMalicious (score: 99)
ALYacGen:Variant.Zusy.396065
CylanceUnsafe
ZillyaTrojan.Injector.Win32.633021
SangforTrojan.Win32.Noon.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Injector.95394949
K7GWTrojan ( 005469fb1 )
Cybereasonmalicious.fcb312
CyrenW32/Injector.TIPS-4567
SymantecTrojan.Formbook!g1
ESET-NOD32a variant of Win32/Injector.EDGI
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan-Spy.Win32.Noon.gen
BitDefenderGen:Variant.Zusy.396065
NANO-AntivirusTrojan.Win32.Inject.fmneey
MicroWorld-eScanGen:Variant.Zusy.396065
TencentWin32.Trojan-spy.Noon.Lgtn
Ad-AwareGen:Variant.Zusy.396065
SophosMal/Generic-S
ComodoMalware@#549k9xicq2bl
BitDefenderThetaAI:Packer.8B25C83819
TrendMicroTrojan.Win32.COSMU.SM
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
FireEyeGeneric.mg.305bd8bfcb312b44
EmsisoftGen:Variant.Zusy.396065 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Noon.eob
AviraTR/Injector.lyriu
eGambitUnsafe.AI_Score_78%
Antiy-AVLTrojan/Generic.ASMalwS.2A6D474
MicrosoftTrojan:Win32/Occamy.C8F
GDataGen:Variant.Zusy.396065
McAfeeGenericR-ORT!305BD8BFCB31
MAXmalware (ai score=100)
VBA32BScope.Trojan.Inject
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.COSMU.SM
YandexTrojan.GenAsa!WZznaStrDRs
IkarusTrojan-Spy.Primarypass
MaxSecureTrojan.Malware.73698928.susgen
FortinetW32/GenKryptik.EKLE!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Zusy.396065?

Zusy.396065 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment