Malware

What is “Zusy.400670”?

Malware Removal

The Zusy.400670 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.400670 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • The executable used a known stolen/malicious Authenticode signature

Related domains:

z.whorecord.xyz

How to determine Zusy.400670?


File Info:

crc32: 90A1C3FD
md5: d362d9699e011eaa80e5e92fae3caff6
name: D362D9699E011EAA80E5E92FAE3CAFF6.mlw
sha1: 4c5c63eeb83387e2f66af097582a946f6918a129
sha256: f3c5f0f97e17e6150c21c1b84acdf93583abf8e2fd970482f916a96c2f027569
sha512: b48cb682a1e72b72babec853f0eadd33cb0b43d121295455ee33b81fbbba05a6db4eca98b1c518bd0896b81f2fede58754003ba507d888cf80c9a6fb7d00e28b
ssdeep: 6144:ucMjm6HFa18fW5fTGxf8K/45X9I4sBODK99VJTu2YL:ucMjDE1+6Y8KetIfOAjR4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.400670 also known as:

Elasticmalicious (high confidence)
CAT-QuickHealTrojan.Kovter.P4
McAfeeGenericRXFB-MN!D362D9699E01
CylanceUnsafe
ZillyaTrojan.KovterCRTD.Win32.2048
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Zusy.400670
K7GWTrojan ( 004c341a1 )
K7AntiVirusTrojan ( 004eb2281 )
BaiduWin32.Trojan.Cerber.b
CyrenW32/Cerber.U.gen!Eldorado
SymantecTrojan.Gen
ESET-NOD32Win32/Kovter.C
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Zerber.hnz
AlibabaRansom:Win32/Zerber.f3799228
NANO-AntivirusTrojan.Win32.Kovter.efutcg
TencentMalware.Win32.Gencirc.10b78ecf
Ad-AwareGen:Variant.Zusy.400670
SophosML/PE-A + Troj/HkMain-DT
ComodoTrojWare.Win32.Kovter.BH@6hsmol
DrWebTrojan.Kovter.297
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXFB-MN!D362D9699E01
FireEyeGeneric.mg.d362d9699e011eaa
EmsisoftGen:Variant.Zusy.400670 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Zerber.ol
WebrootW32.Trojan.Kovter
AviraHEUR/AGEN.1128763
ArcabitTrojan.Zusy.D61D1E
SUPERAntiSpywareTrojan.Agent/Gen-Kovter
ZoneAlarmTrojan-Ransom.Win32.Zerber.hnz
MicrosoftTrojan:Win32/Kovter
AhnLab-V3Win-Trojan/Cerber.Gen
Acronissuspicious
TACHYONRansom/W32.Cerber.341848
MalwarebytesTrojan.Kovter
YandexTrojan.GenAsa!xFvY3pSq4zU
IkarusTrojan.Win32.Filecoder
FortinetW32/Injector.DBHU!tr
PandaTrj/CI.A

How to remove Zusy.400670?

Zusy.400670 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment