Malware

Zusy.398071 (file analysis)

Malware Removal

The Zusy.398071 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.398071 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.398071?


File Info:

crc32: 572C0023
md5: 2785ccea7fa1c589f285ad76220be262
name: 2785CCEA7FA1C589F285AD76220BE262.mlw
sha1: 5df8946ac46e35c32b9091fdbf75fe4142c7755a
sha256: 13df51a724ee49603e7dc74e4a6f5c9541828773dbeb19d6a14dd23f2b202c93
sha512: 8d590665bef770ce2766e985760f3df5858f0f0380fc06ef0c364355943e702091e000dd9264e248e8d34bd03d60529672758c0353675e89811b016dca90e649
ssdeep: 24576:EAbsQMK23A4Oe0QXnnCILzt7AfIAa4XiHWh1fQ:EAgl3A4FXnnCILzt7AAAa2iif
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2016
InternalName: system_b.exe
FileVersion: 0.9.0.23
CompanyName: MiniTool
ProductName: MiniTool ShadowMaker
ProductVersion: 0.9.0.23
FileDescription: MiniTool ShadowMaker
OriginalFilename: system_b.exe
Translation: 0x0409 0x04b0

Zusy.398071 also known as:

K7AntiVirusTrojan ( 0055fdd91 )
LionicTrojan.Win32.Staser.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.398071
CylanceUnsafe
SangforTrojan.Win32.Staser.gen
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojan:Win32/Staser.cd39e282
K7GWTrojan ( 0055fdd91 )
Cybereasonmalicious.ac46e3
CyrenW32/Kryptik.FAD.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HATU
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Staser.gen
BitDefenderGen:Variant.Zusy.398071
NANO-AntivirusTrojan.Win32.Staser.jcclck
MicroWorld-eScanGen:Variant.Zusy.398071
TencentWin32.Trojan.Staser.Hrpd
Ad-AwareGen:Variant.Zusy.398071
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Tewgol.cjfbz
BitDefenderThetaGen:NN.ZexaF.34294.UA0@aCSjmUbi
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WHM21
McAfee-GW-EditionBehavesLike.Win32.Ransomware.vm
FireEyeGeneric.mg.2785ccea7fa1c589
EmsisoftGen:Variant.Zusy.398071 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.Tewgol.cjfbz
Antiy-AVLTrojan/Win32.Staser
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
ArcabitTrojan.Zusy.D612F7
GDataWin32.Trojan.PSE.1DTPNY9
AhnLab-V3Trojan/Win.Generic.R438196
McAfeeGenericRXPV-GW!2785CCEA7FA1
MAXmalware (ai score=80)
VBA32Trojan.Staser
MalwarebytesAdware.DownloadAssistant
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0WHM21
RisingTrojan.Kryptik!1.AA55 (CLASSIC)
YandexTrojan.Staser!hTIhzvxa8Gk
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.73802172.susgen
FortinetW32/Kryptik.HATU!tr
AVGWin32:CrypterX-gen [Trj]
Paloaltogeneric.ml

How to remove Zusy.398071?

Zusy.398071 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment