Malware

Zusy.401170 removal instruction

Malware Removal

The Zusy.401170 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.401170 virus can do?

  • Crashed cuckoomon during analysis. Report this error to the Github repo.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.401170?


File Info:

crc32: F4D69268
md5: e52c84a4c817369e12b414d579cc8c96
name: E52C84A4C817369E12B414D579CC8C96.mlw
sha1: 6de8db8f11d453b731cfbdaa900ff4618a0e0b82
sha256: 17d18971ef01526fb5a4c3c307ddbc2229b9ffe1e5b9dac4c69299aafa8cc65a
sha512: 60a8e86e9bdbcdd5101ae7c1437146d02cfa02a54e0965698028deb818d3b6915b5ffdfda4628f436a525fd4f872b32f47729eeb1d86f0c9ce8be5c7568b43ab
ssdeep: 6144:r38MTSOBmdIwYTjzEu67sRUDRmUrC2fsu1t73NII:rMMneILEuDSDcqTLN3qI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2015 UltraVNC team members
InternalName: VNCViewer
FileVersion: 1.2.0.9
CompanyName: UltraVNC
Comments: UltraVNC Viewer
ProductName: UltraVNC VNCViewer
ProductVersion: 1.2.0.9
FileDescription: VNCViewer
OriginalFilename: VNCViewer.exe
Translation: 0x0000 0x04b0

Zusy.401170 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004dd2a01 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.AVKill.59817
CAT-QuickHealRansom.Crowti.WR7
McAfeeGenericR-FWD!E52C84A4C817
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.860299
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 004dd2a01 )
Cybereasonmalicious.4c8173
CyrenW32/Agent.XL.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.EMIR
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.401170
NANO-AntivirusTrojan.Win32.AVKill.eatyzk
MicroWorld-eScanGen:Variant.Mikey.31178
TencentWin32.Trojan.Generic.Ahya
Ad-AwareGen:Variant.Mikey.31178
SophosML/PE-A + Mal/Wonton-CB
BitDefenderThetaGen:NN.ZexaF.34142.Ki0@a01VoZn
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPTESLA.SMM1
McAfee-GW-EditionBehavesLike.Win32.Dropper.hz
FireEyeGeneric.mg.e52c84a4c817369e
EmsisoftGen:Variant.Mikey.31178 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.ejzlz
AviraHEUR/AGEN.1127894
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Tescrypt.D
ArcabitTrojan.Mikey.D79CA
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
GDataGen:Variant.Mikey.31178
AhnLab-V3Trojan/Win32.Teslacrypt.C1321714
VBA32Malware-Cryptor.Limpopo
MAXmalware (ai score=100)
MalwarebytesMalware.AI.3234354602
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_CRYPTESLA.SMM1
RisingTrojan.Generic@ML.87 (RDML:H8WNjdFm00jYh+H+ySJ6Qw)
IkarusTrojan-Ransom.TeslaCrypt4
FortinetW32/Kryptik.EMIR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Zusy.401170?

Zusy.401170 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment