Malware

Zusy.398846 removal instruction

Malware Removal

The Zusy.398846 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.398846 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.398846?


File Info:

crc32: 94134331
md5: d228d41f0813904505f055c75da4d998
name: D228D41F0813904505F055C75DA4D998.mlw
sha1: 9995a7e68d50faa6cd726b662f0d064f7636a763
sha256: f7582c28e0c20b42f939be3111a460364c469fa37d8148d8497ce56cf98faeeb
sha512: 54c4012feca0627f7a5dba77b850ea5f828649bbece9b4844a5ff98ce0ecb3c8554f5618ed0836cd1f7942f91586cce6cbbf1553352b7288c06586ddd84feadb
ssdeep: 3072:aA8JmK7ATVfQeVqNFZa/9KzMXJ6jTFDlAwqWut5KZMzfeAAAoio:azIqATVfQeV2FZalKq6jtGJWuTmd
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1997-2006 The PHP Group
InternalName: xiu_lridh.dll
FileVersion: 3.3.0.0
CompanyName: The PHP Group
URL: http://www.php.net
PrivateBuild:
LegalTrademarks: PHP
Comments: Thanks to Zeev Suraski, Zak Greant, Georg Richter
ProductName: XIU lri_hfhqn.dll
SpecialBuild:
ProductVersion: 3.3.0
FileDescription: MySQL
OriginalFilename: xiu_lridh.dll
Translation: 0x0409 0x04b0

Zusy.398846 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Dridex.776
ClamAVWin.Packed.Wacatac-9888486-0
ALYacGen:Variant.Zusy.398846
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005816e51 )
K7AntiVirusTrojan ( 005816e51 )
CyrenW32/Dridex.EV.gen!Eldorado
SymantecPacked.Generic.517
ESET-NOD32a variant of Win32/Kryptik.HMFO
APEXMalicious
AvastWin32:BankerX-gen [Trj]
CynetMalicious (score: 100)
KasperskyUDS:Trojan-Downloader.Win32.Cridex
BitDefenderGen:Variant.Zusy.398846
MicroWorld-eScanGen:Variant.Zusy.398846
Ad-AwareGen:Variant.Zusy.398846
SophosMal/Generic-R + Mal/EncPk-APX
BitDefenderThetaGen:NN.ZedlaF.34110.lu8@aqRSzdli
McAfee-GW-EditionBehavesLike.Win32.Rootkit.cc
FireEyeGeneric.mg.d228d41f08139045
EmsisoftGen:Variant.Zusy.398846 (B)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Sabsik.TE.B!ml
GDataGen:Variant.Zusy.398846
AhnLab-V3Trojan/Win.BankerX-gen.R438891
Acronissuspicious
McAfeeArtemis!D228D41F0813
MAXmalware (ai score=82)
MalwarebytesTrojan.Dridex
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.83 (RDML:sbAYhvUlaZW4PHpnS5CYSQ)
IkarusTrojan-Banker.Dridex
FortinetW32/Kryptik.HMFO!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml

How to remove Zusy.398846?

Zusy.398846 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment