Malware

Zusy.396318 removal guide

Malware Removal

The Zusy.396318 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.396318 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Collects information to fingerprint the system

Related domains:

static.43.47.69.159.clients.your-server.de

How to determine Zusy.396318?


File Info:

crc32: 47C21FB3
md5: ec394b46caa7cdbeb60c845b378d76a9
name: EC394B46CAA7CDBEB60C845B378D76A9.mlw
sha1: fcda38279775ed7d8cecde1ba334828aa600642e
sha256: 1a10afd2c50d7f6627a1f5fbc15870bc2c2a113aac8678a069186bb6b9c15927
sha512: e6aa05b6cde3f2494f54e4a1ec5569b99462cd32a7a1165683196f79da6ec91b329dce47618762d9f865dfb89422ddb9d0d3b5552b6a0c9a9c43bee1753727e9
ssdeep: 24576:ARmZxo05JmgbyX4n9F08ii/XZkjUc6am7Xu1pPC:0mZdJbbKAvBB06aC+1RC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: ABRepair.exe
FileVersion: 3.1.1080.26
Comments: free installer
ProductName: Framework 3.14 Setup
ProductVersion: 3.1.1080.26
FileDescription: Framework 3.14 Setup
OriginalFilename: ABRepair.exe
Translation: 0x0409 0x04b0

Zusy.396318 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053a5771 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.3683
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Chapak.S3456034
ALYacGen:Variant.Zusy.396318
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1470517
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:Win32/Katusha.32865dfc
K7GWTrojan ( 0053a5771 )
Cybereasonmalicious.6caa7c
CyrenW32/Trojan.CIW.gen!Eldorado
SymantecPUA.ICLoader
ESET-NOD32a variant of Win32/Kryptik.GJYD
APEXMalicious
AvastWin32:AdwareSig [Adw]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.396318
NANO-AntivirusTrojan.Win32.Ekstak.fhmkvo
MicroWorld-eScanGen:Variant.Zusy.396318
TencentMalware.Win32.Gencirc.10cc4f36
Ad-AwareGen:Variant.Zusy.396318
SophosGeneric PUA PM (PUA)
ComodoApplication.Win32.ICLoader.GS@84429a
McAfee-GW-EditionPacked-FKX!EC394B46CAA7
FireEyeGeneric.mg.ec394b46caa7cdbe
EmsisoftApplication.InstallMon (A)
SentinelOneStatic AI – Malicious PE
AviraTR/ICLoader.Gen8
Antiy-AVLTrojan/Generic.ASBOL.C513
MicrosoftPUADlManager:Win32/InstallCube
ArcabitTrojan.Zusy.D60C1E
ZoneAlarmHEUR:Packed.Win32.Katusha.gen
GDataGen:Variant.Zusy.396318
AhnLab-V3PUP/Win32.ICLoader.R234861
Acronissuspicious
McAfeePacked-FKX!EC394B46CAA7
VBA32BScope.Trojan.Ekstak
MalwarebytesAdware.InstallCube
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.GenAsa!zb8Sl8Htyvk
IkarusPUA.ICLoader
MaxSecureTrojan.Packed.WIN32.Katusha.gen_216068
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareSig [Adw]

How to remove Zusy.396318?

Zusy.396318 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment