Malware

Zusy.398931 removal guide

Malware Removal

The Zusy.398931 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.398931 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Arabic (Oman)

Related domains:

cdn.discordapp.com
ocsp.digicert.com

How to determine Zusy.398931?


File Info:

crc32: 36B1C2AB
md5: 20f8196b6f36e4551d1254d3f8bcd829
name: 20F8196B6F36E4551D1254D3F8BCD829.mlw
sha1: 8932669b409dbd2abe2039d0c1a07f71d3e61ecd
sha256: 1af55649a731abb95d71e2e49693a7bcf87270eb4f8712b747f7e04a0a2a3031
sha512: 75e533ca9fba59e522c3307c78052ab367a507c9bc9b3d5bdb25dfb9a0a67941920ec832f592de319e929512ae2c84df4ca9a73f785030aa8c9c98cce735bccb
ssdeep: 12288:y6Mx93Pohy2krjuOmUORtyncxQRhJJzhoqgH5sB4dxHGYV:y6C5PYczORhQRh9B4dd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2021 PowerBoost
InternalName: PowerBoost.exe
FileVersion: 3225.42.1.15
CompanyName: PowerBoost
ProductName: PowerBoost
ProductVersion: 3225.42.1.15
FileDescription: PowerBoost
OriginalFilename: PowerBoost.exe
Translation: 0x0009 0x04b0

Zusy.398931 also known as:

K7AntiVirusTrojan-Downloader ( 005815f81 )
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.398931
CylanceUnsafe
SangforTrojan.Win32.Miner.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDownloader:Win32/Miner.bbde684a
K7GWTrojan-Downloader ( 005815f81 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.FUZ
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-Downloader.Win32.Miner.gen
BitDefenderGen:Variant.Zusy.398931
MicroWorld-eScanGen:Variant.Zusy.398931
TencentWin32.Trojan-downloader.Miner.Hrpg
Ad-AwareGen:Variant.Zusy.398931
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34110.!u0@a8TN80jO
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
FireEyeGen:Variant.Zusy.398931
EmsisoftGen:Variant.Zusy.398931 (B)
JiangminTrojanDownloader.Miner.di
WebrootW32.Trojan.Gen
AviraTR/Dldr.Agent.xveme
eGambitUnsafe.AI_Score_85%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Azorult!ml
ZoneAlarmHEUR:Trojan-Downloader.Win32.Miner.gen
GDataWin32.Trojan.PSE.1OORW7L
AhnLab-V3Dropper/Win.Mudrop.C4611786
McAfeeGenericRXPU-SK!20F8196B6F36
MAXmalware (ai score=80)
VBA32BScope.Trojan.Chapak
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
RisingTrojan.Generic@ML.92 (RDML:gjVFJO3a0/MRKpk5+DudGg)
IkarusTrojan-Downloader.Win32.Agent
FortinetRiskware/Miner
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Zusy.398931?

Zusy.398931 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment