Malware

What is “Zusy.401617”?

Malware Removal

The Zusy.401617 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.401617 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Zusy.401617?


File Info:

crc32: CD26C6A8
md5: c1a3f5621ab05685f17e73cfc86367fe
name: C1A3F5621AB05685F17E73CFC86367FE.mlw
sha1: 272ecc27160f16d6c8e89c8387ebd185e049e5a1
sha256: bd62fc2450fb37335e718e4a514ac7bd79a8a14056d1b1088a1726b46b10caf5
sha512: bf3e4e100b6069abb584c4ff13bf53e70827238c9ee2ac307a169ead54105d93ae93935e10b81769fc1111b1f6a236db519533d809dc75626d5191af8b96eb05
ssdeep: 24576:hn5XKcnJedPPOToAmWl4yGgSVtlsislVlNd1C1:h5pnJGPPOTbmWl41gS/lslt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.401617 also known as:

K7AntiVirusTrojan ( 005821bc1 )
LionicTrojan.Win32.Staser.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.StaserIH.S22804401
ALYacGen:Variant.Zusy.401617
CylanceUnsafe
SangforTrojan.Win32.Staser.gen
CrowdStrikewin/malicious_confidence_60% (W)
K7GWTrojan ( 005821bc1 )
Cybereasonmalicious.7160f1
CyrenW32/FakeAlert.FY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLQM
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Staser.gen
BitDefenderGen:Variant.Zusy.401617
MicroWorld-eScanGen:Variant.Zusy.401617
Ad-AwareGen:Variant.Zusy.401617
BitDefenderThetaGen:NN.ZexaF.34266.eAW@ae8X9Cji
TrendMicroTROJ_GEN.R002C0PIR21
McAfee-GW-EditionBehavesLike.Win32.Dropper.vh
FireEyeGeneric.mg.c1a3f5621ab05685
EmsisoftGen:Variant.Zusy.401617 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.Tewgol.mljfh
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.PSE.1IAKRUN
AhnLab-V3Trojan/Win.CrypterX-gen.C4639919
McAfeeGenericRXQC-BH!C1A3F5621AB0
MAXmalware (ai score=82)
VBA32Trojan.Staser
MalwarebytesAdware.Agent.SFP.Generic
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PIR21
RisingTrojan.Kryptik!1.AA55 (CLASSIC)
YandexTrojan.Staser!olEyXgGz0lc
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HATU!tr
AVGWin32:CrypterX-gen [Trj]
Paloaltogeneric.ml

How to remove Zusy.401617?

Zusy.401617 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment