Malware

What is “Zusy.398649”?

Malware Removal

The Zusy.398649 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.398649 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Anomalous binary characteristics

Related domains:

trick.matchoatmeal.icu
fuss.wavesfork.online

How to determine Zusy.398649?


File Info:

crc32: 5CE9E8CE
md5: 718313fac8e0b42ead831201331aa201
name: 718313FAC8E0B42EAD831201331AA201.mlw
sha1: 50fcb9d9440e6f2381398a1dd1f0ee46dfb006ef
sha256: 1de6e2426a26062db814203f707fe2f56def402ef75202c212df30701c812bf2
sha512: 178f06b11792656d3f5bedc2fe9d0907b2bffe1bd53d7d67afb799c7d975f7d93b22dc030752e0826a681c6c2878fc43da88eaec89ace8c4c78b6972b5c55536
ssdeep: 24576:gAoHHQOmymcR8s0aAVr61k83B2XihiI2mju47QgRv4OuAurp6:1qwQmD4Ad3MhiGuTvT6
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9Utoteedenelr odcuawsitean
InternalName: SOHUKOSOETMOUM.EXE
FileVersion: 4.1.6.4
CompanyName: xa9Utoteedenelr odcuawsitean
ProductName: SOHUKOSOETMOUM
ProductVersion: 4.1.6.4
OriginalFilename: sohukosoetmoum.exe
Translation: 0x0409 0x04e4

Zusy.398649 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053e8a41 )
LionicTrojan.Win32.Strictor.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.398649
CylanceUnsafe
AlibabaAdWare:Win32/StartSurf.7655a6fb
K7GWTrojan ( 0053e8a41 )
Cybereasonmalicious.ac8e0b
CyrenW32/Kryptik.DID.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GLRL
APEXMalicious
AvastWin32:LoadMoney-ATT [Adw]
Kasperskynot-a-virus:HEUR:AdWare.Win32.StartSurf.gen
BitDefenderGen:Variant.Zusy.398649
NANO-AntivirusRiskware.Win32.StartSurf.fjvglq
MicroWorld-eScanGen:Variant.Zusy.398649
TencentMalware.Win32.Gencirc.114d4dd5
Ad-AwareGen:Variant.Zusy.398649
SophosMal/Generic-S + IStartSurfInstaller (PUA)
ComodoApplication.Win32.Dlhelper.GL@81g4fd
BitDefenderThetaGen:NN.ZexaF.34266.Uw0@auwD5mpi
McAfee-GW-EditionPacked-FKC!718313FAC8E0
FireEyeGeneric.mg.718313fac8e0b42e
EmsisoftGen:Variant.Zusy.398649 (B)
SentinelOneStatic AI – Malicious PE
JiangminAdWare.StartSurf.bwjr
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.28C3B29
MicrosoftPWS:Win32/Zbot!ml
GDataGen:Variant.Zusy.398649
Acronissuspicious
McAfeePacked-FKC!718313FAC8E0
MAXmalware (ai score=94)
VBA32BScope.Adware.Prepscram
MalwarebytesTrojan.IStartSurf
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.B33C (CLASSIC)
IkarusPUA.Dlhelper
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AP.21CC80!tr
AVGWin32:LoadMoney-ATT [Adw]
Paloaltogeneric.ml

How to remove Zusy.398649?

Zusy.398649 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment