Malware

What is “Zusy.396646”?

Malware Removal

The Zusy.396646 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.396646 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs

How to determine Zusy.396646?


File Info:

crc32: 74511A4A
md5: a7428579d8f9352ffb2496d24cf9c3df
name: A7428579D8F9352FFB2496D24CF9C3DF.mlw
sha1: dc31bfc2f33921a9651c30da5009e95849c0f756
sha256: 298b2431e5c5527fe431fcc8de531152d5ac07f838b28ad2a79c0101ea2b6b90
sha512: 374e4b801c27563432e64413309452adedb42d853d169151386b44c599d812a64f5718082f11d74a2182c85d9ae97459d4af77bfb099399448cbb1de49f6390e
ssdeep: 6144:hGImCBzQ1dauirwS5/NllSuWF5KvQ8HWBhdl2BiE:hGImCBzQ1wlLOuiAI82BRciE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.396646 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Reline.i!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.396646
CylanceUnsafe
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojanPSW:Win32/GenKryptik.c66c7913
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.2f3392
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/GenKryptik.FILD
APEXMalicious
AvastWin32:PWSX-gen [Trj]
BitDefenderGen:Variant.Zusy.396646
MicroWorld-eScanGen:Variant.Zusy.396646
TencentWin32.Trojan-qqpass.Qqrob.Llqo
Ad-AwareGen:Variant.Zusy.396646
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34058.NuZ@a0VXaocc
McAfee-GW-EditionBehavesLike.Win32.Picsys.jm
FireEyeGeneric.mg.a7428579d8f9352f
EmsisoftGen:Variant.Zusy.396646 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Kryptik.giawu
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:MSIL/Cryptor
ArcabitTrojan.Zusy.D60D66
GDataMSIL.Trojan-Stealer.NetSteal.161I5K
McAfeeRDN/Generic PWS.y
MAXmalware (ai score=87)
VBA32Malware-Cryptor.Inject.gen
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H0CH621
RisingBackdoor.Mokes!1.CECE (CLASSIC)
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Reline.FILD!tr.pws
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanPSW.Generic.HwIAF2EA

How to remove Zusy.396646?

Zusy.396646 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment