Malware

Zusy.148936 malicious file

Malware Removal

The Zusy.148936 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.148936 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.148936?


File Info:

crc32: 3C336D40
md5: f3b85ca91d44cbb5138188b602e1b203
name: F3B85CA91D44CBB5138188B602E1B203.mlw
sha1: 4650b82c9a0219885b4118619b5e18d15edbeb90
sha256: 38bc2465c9a82ba98c8c4e8f2e9d394a8903b6d1857690aa666ae275037be64a
sha512: 64f7ae4554d3a90dbf880ae9cea42bbaba1b7bfd5f870aeb14746dc1f9a854d07c33fc9a8a4690fbc4ec31319e7ea5ea12bd0b6f1ae04cc63e66b9f67d2931b1
ssdeep: 6144:vE8zQijglaZF40zCGmC6amy45+H5ijyBqf:vEeC052yBS
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Copyright (C) 1995-2004 Joerg Schilling
InternalName: cdrecord
FileVersion: 2.01-13
CompanyName: EASEUS
ProductName: EASEUS CDRecord
ProductVersion: 2.01-13
FileDescription: CD recording backend
OriginalFilename: cdrecord.exe
Translation: 0x0000 0x0000

Zusy.148936 also known as:

K7AntiVirusTrojan ( 004cd4361 )
LionicTrojan.Win32.Blocker.j!c
DrWebTrojan.Winlock.11938
CynetMalicious (score: 99)
ALYacGen:Variant.Zusy.148936
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.30396
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Blocker.f12f361c
K7GWTrojan ( 004cd4361 )
Cybereasonmalicious.91d44c
CyrenW32/S-8c43438c!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.DODC
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.hjii
BitDefenderGen:Variant.Zusy.148936
NANO-AntivirusTrojan.Win32.Blocker.dtoyfl
MicroWorld-eScanGen:Variant.Zusy.148936
TencentWin32.Trojan.Blocker.Ednk
Ad-AwareGen:Variant.Zusy.148936
SophosML/PE-A + Troj/Urausy-AG
ComodoMalware@#3k39w79yhm50t
BitDefenderThetaGen:NN.ZexaF.34058.py0@a46GrAm
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R034E03JA15
McAfee-GW-EditionBehavesLike.Win32.Dropper.dh
FireEyeGeneric.mg.f3b85ca91d44cbb5
EmsisoftGen:Variant.Zusy.148936 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1102614
Antiy-AVLTrojan/Generic.ASMalwS.120A1FE
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftVirTool:Win32/Obfuscator.ANA
ArcabitTrojan.Zusy.D245C8
ZoneAlarmTrojan-Ransom.Win32.Blocker.hjii
GDataGen:Variant.Zusy.148936
AhnLab-V3Malware/Win32.Generic.C946254
Acronissuspicious
McAfeeArtemis!F3B85CA91D44
MAXmalware (ai score=82)
VBA32BScope.Trojan.Bagsu
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R034E03JA15
RisingTrojan.Generic@ML.90 (RDML:haV6I6PkjwwrDUtzukw6NQ)
YandexTrojan.Blocker!WWfNUB95Zpo
IkarusTrojan.Win32.LockScreen
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HxQBEpsA

How to remove Zusy.148936?

Zusy.148936 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment