Malware

Zusy.405968 removal instruction

Malware Removal

The Zusy.405968 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.405968 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Ukrainian
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.405968?


File Info:

crc32: D1B47D2D
md5: c7d301bbc84a489e3e88cc53cbc935e3
name: C7D301BBC84A489E3E88CC53CBC935E3.mlw
sha1: 0ee3585a193934ef9d1a79dde2e93aa0ae9283d4
sha256: c10e29cb4fddbefbe09ad934a11e13106fc4bca07b248449f6aa9cdb9983639a
sha512: b65d0d35cf939170dd3ad45f3bf13cacc7b051317147b8276e8b97cb3b228ee073a97dcf013f1af9af0a30c75709f37552cc096e653d4bf1d66aefdc7e926d48
ssdeep: 24576:CLkROkFVTkV8k6ekckgkf3ZkPA0UDJa4nq5qfzNLm:qkROk7TkWk6ekckgkBkPA0qjnffzNL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018 Ariolic Software, Ltd
InternalName: asmartCore
FileVersion: 2.10.2.167
CompanyName: Ariolic Software, Ltd. (www.ariolic.com)
Comments: ab28886af3b6f732ef902aaf66703c121f6899eb
ProductName: ActiveSMART
ProductVersion: 2.10.2.167
FileDescription: ActiveSMART (R) - Hard drive health and files audit utility
OriginalFilename: ASmartCore.exe
Translation: 0x0409 0x04b0

Zusy.405968 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0058214e1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.405968
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
K7GWTrojan ( 0058214e1 )
Cybereasonmalicious.a19393
CyrenW32/Kryptik.FRS.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HBAI
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
KasperskyHEUR:Backdoor.Win32.TeviRat.gen
BitDefenderGen:Variant.Zusy.405968
MicroWorld-eScanGen:Variant.Zusy.405968
Ad-AwareGen:Variant.Zusy.405968
SophosMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.th
FireEyeGeneric.mg.c7d301bbc84a489e
EmsisoftGen:Variant.Zusy.405968 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.Tewgol.dtett
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataWin32.Trojan.PSE.1IAKRUN
AhnLab-V3Trojan/Win.Generic.R448616
McAfeeGenericRXOV-UA!C7D301BBC84A
MAXmalware (ai score=88)
MalwarebytesAdware.DownloadAssistant
RisingMalware.Heuristic!ET#87% (RDMK:cmRtazq8Kb1ChoKUNckcSUFsZRb/)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HATU!tr
AVGWin32:CrypterX-gen [Trj]

How to remove Zusy.405968?

Zusy.405968 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment