Malware

Zusy.396220 malicious file

Malware Removal

The Zusy.396220 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.396220 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)

Related domains:

z.whorecord.xyz
a.tomx.xyz
idking.f3322.net

How to determine Zusy.396220?


File Info:

crc32: 699C5AA9
md5: c65f581e9a6b9e3802132a1452b4917b
name: C65F581E9A6B9E3802132A1452B4917B.mlw
sha1: cf151da7e9e5076201953bd857d33ddbe8279e6d
sha256: 1a2ddedf38d6f0f82d64a49b8feb5068d272de243df84b3f4450441dc3079d7f
sha512: 3a32138552fca785a820be619b2e5b7d67b14206456fcf511aed7385f809e9afb1312e117dd8d13aff4da0d59a4fc4d369182aed8c0d1dbb65966b7ddf767720
ssdeep: 768:2UAdG4fQmpPdFjsfx4xz7cfyl0NEvNJgujin8o2Sm9Y5frmJRb4rv1vZIo:2UOGURPdI+4KJrs+Sm65jmDu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 2001
InternalName: 2_1
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: 2_1 x5e94x7528x7a0bx5e8f
ProductVersion: 1, 0, 0, 1
FileDescription: 2_1 Microsoft x57fax7840x7c7bx5e94x7528x7a0bx5e8f
OriginalFilename: 2_1.EXE
Translation: 0x0804 0x04b0

Zusy.396220 also known as:

K7AntiVirusTrojan ( 0053af701 )
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.Zusy.396220
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaBackdoor:Win32/Siscos.b13d04a0
K7GWTrojan ( 0053af701 )
Cybereasonmalicious.e9a6b9
BaiduWin32.Trojan.KillAV.c
CyrenW32/KillAV.AU.gen!Eldorado
SymantecBackdoor.Zegost
ESET-NOD32a variant of Win32/Farfli.CMC
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Generic-6305873-0
KasperskyTrojan.Win32.Siscos.yee
BitDefenderGen:Variant.Zusy.396220
NANO-AntivirusTrojan.Win32.Siscos.fhrpoe
MicroWorld-eScanGen:Variant.Zusy.396220
TencentWin32.Trojan.Siscos.Sxoh
Ad-AwareGen:Variant.Zusy.396220
ComodoMalware@#2mndkqx2ay6u4
BitDefenderThetaGen:NN.ZexaF.34236.fq1@aq3OyVab
TrendMicroBKDR_FARFLI.SMP
McAfee-GW-EditionGeneric.dye
FireEyeGeneric.mg.c65f581e9a6b9e38
EmsisoftGen:Variant.Zusy.396220 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1130805
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.27DD6F9
MicrosoftBackdoor:Win32/Zegost.CQ!bit
ArcabitTrojan.Zusy.D60BBC
GDataGen:Variant.Zusy.396220
McAfeeGeneric.dye
MAXmalware (ai score=82)
VBA32BScope.Trojan.Skeeyah
PandaTrj/GdSda.A
TrendMicro-HouseCallBKDR_FARFLI.SMP
RisingBackdoor.Farfli!1.64B3 (CLASSIC)
YandexTrojan.Siscos!1YddN+QecCg
IkarusTrojan.Win32.Farfli
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Farfli.CMC!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Zusy.396220?

Zusy.396220 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment