Malware

Should I remove “Zusy.399672”?

Malware Removal

The Zusy.399672 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.399672 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

api.2ip.ua
securebiz.org
astdg.top
gheorghip.tumblr.com
ocsp.comodoca.com
ocsp.usertrust.com
ocsp.sectigo.com

How to determine Zusy.399672?


File Info:

crc32: 3FC5B144
md5: 86bf97a73961681c435c4b3972c0837e
name: 86BF97A73961681C435C4B3972C0837E.mlw
sha1: e88187b6fba9ba709903d39fab8a23b6404ddd0c
sha256: f5a2d62a1d09f34f73adc253887b665c96a2fbf7cadc6084569675da186357e1
sha512: f806c0f037be29a9424e2cbe861401b3acfbc057f641afe1ae2e285cace937a9400093187c86347b4e2edf929306b9f9af448dd617f4ab1f23f70605f1ee6c49
ssdeep: 12288:eg4rSVzZAIILcX8pGoo1HH/aJ7Avy8DIx+qKLlvSrbHPRHncczx8AV9UzsVuOTnb:egqiZAIILcwhgn/0A7m+T+rRHNxxusxP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: sagzmioloku.axi
ProductVersion: 7.19.28.123
Copyright: Copyrighz (C) 2021, fudkageta
Translation: 0x0181 0x022e

Zusy.399672 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005819401 )
LionicTrojan.Win32.Stop.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.1937
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Stop
CylanceUnsafe
ZillyaTrojan.Stop.Win32.1896
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Azorult.8264e7be
K7GWTrojan ( 005819401 )
Cybereasonmalicious.6fba9b
CyrenW32/Kryptik.EWJ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMGT
APEXMalicious
AvastWin32:DropperX-gen [Drp]
ClamAVWin.Dropper.Fragtor-9889202-0
KasperskyHEUR:Trojan-Ransom.Win32.Stop.gen
BitDefenderGen:Variant.Zusy.399672
MicroWorld-eScanGen:Variant.Zusy.399672
TencentMalware.Win32.Gencirc.11cbc3de
Ad-AwareGen:Variant.Zusy.399672
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34126.Qq1@aeVWd8jG
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.86bf97a73961681c
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Stop.aud
AviraTR/AD.InstaBot.jfghc
Antiy-AVLTrojan/Generic.ASMalwS.348BD81
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Azorult.RM!MTB
GridinsoftRansom.Win32.STOP.dd!s1
GDataWin32.Trojan.BSE.13K4JBF
AhnLab-V3Trojan/Win.MalPE.R439380
McAfeePacked-GDT!86BF97A73961
MAXmalware (ai score=82)
VBA32Backdoor.Mokes
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.D91D (CLASSIC)
YandexTrojan.Kryptik!Zp+6bpoAEPs
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HMGU!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml

How to remove Zusy.399672?

Zusy.399672 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment