Malware

Zusy.396617 removal

Malware Removal

The Zusy.396617 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.396617 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Anomalous binary characteristics

Related domains:

alt.tubgiants.host
com.bushesstocking.icu

How to determine Zusy.396617?


File Info:

crc32: E81E99FA
md5: 2ac16cf0ef8cd002f23d991c14836c5f
name: 2AC16CF0EF8CD002F23D991C14836C5F.mlw
sha1: d336c89b92655f82b33fefa9b55bf17ff82c3950
sha256: 215460159b4db7c50c4ec5fb47a0df44e2d60c1705ab6cb774bdb358ccd4c042
sha512: 2d2b50fb548b7f290260f49730b74c208ad4700a7796faeffd9053a71c17c1d90c780768a533f0956c1caaf237095c99ec9eafd45a635edde91492f28787607f
ssdeep: 24576:TvERqDLI63KyAdBCggEZpnDBApTXaGk/9+8AtvJlsr8p/if9CEdGQxv35rZinPM:TjN3JiBJC2hMxOh9zxZImUx
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9Daberziwitih oriruf
InternalName: AMUHLI.EXE
FileVersion: 1.3.6.5
CompanyName: xa9Daberziwitih oriruf
ProductName: AMUHLI
ProductVersion: 1.3.6.5
OriginalFilename: amuhli.exe
Translation: 0x0409 0x04e4

Zusy.396617 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00549c091 )
Elasticmalicious (high confidence)
DrWebTrojan.Vittalia.17937
CynetMalicious (score: 100)
CAT-QuickHealSwbndlr.Dlhelper.V4
ALYacGen:Variant.Zusy.396617
CylanceUnsafe
ZillyaAdware.StartSurf.Win32.90793
SangforTrojan.Win32.Save.a
AlibabaAdWare:Win32/StartSurf.1046a615
K7GWTrojan ( 00549c091 )
Cybereasonmalicious.0ef8cd
CyrenW32/S-dabc58ac!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GNDZ
APEXMalicious
AvastWin32:StartSurf-I [Adw]
Kasperskynot-a-virus:HEUR:AdWare.Win32.StartSurf.gen
BitDefenderGen:Variant.Zusy.396617
NANO-AntivirusTrojan.Win32.Vittalia.flpcpl
MicroWorld-eScanGen:Variant.Zusy.396617
TencentMalware.Win32.Gencirc.10cd1da8
Ad-AwareGen:Variant.Zusy.396617
SophosIStartSurfInstaller (PUA)
ComodoApplication.Win32.Dlhelper.GJ@8137f9
BitDefenderThetaAI:Packer.1FE37FC321
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.URSNIF.SMY.hp
McAfee-GW-EditionBehavesLike.Win32.Dropper.tz
FireEyeGeneric.mg.2ac16cf0ef8cd002
EmsisoftGen:Variant.Zusy.396617 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.StartSurf.uot
AviraHEUR/AGEN.1101341
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.2A04606
MicrosoftTrojan:Win32/Occamy.C
GDataGen:Variant.Zusy.396617
AhnLab-V3Malware/RL.Generic.R250484
Acronissuspicious
McAfeePacked-FOY!2AC16CF0EF8C
MAXmalware (ai score=96)
VBA32BScope.Adware.StartSurf
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.URSNIF.SMY.hp
RisingTrojan.Kryptik!1.B51F (CLASSIC)
YandexTrojan.GenAsa!eY3OGBmXQNU
IkarusPUA.Win32.Prepscram
MaxSecureWin.MxResIcn.Heur.Gen
FortinetW32/Kryptik.GNDZ!tr
AVGWin32:StartSurf-I [Adw]
Paloaltogeneric.ml

How to remove Zusy.396617?

Zusy.396617 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment