Malware

How to remove “Zusy.240935”?

Malware Removal

The Zusy.240935 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.240935 virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.240935?


File Info:

crc32: EA53386E
md5: a18b7cb1fe97912ffc3e38d76ccc0462
name: A18B7CB1FE97912FFC3E38D76CCC0462.mlw
sha1: c5908c111223d69f532973643381983ba385c1c1
sha256: 2d5e2831e24496bd74a7a2317f824657905cdadaeb00f5c6e33e9b75c5231a2f
sha512: d92025f6eb3ab4a594113813284361694ce1b78cfd513d88f4ea842ea7d37c91976066b33089c4da048e39cc4c65654637d2a14138327df40f89d4bb0963be1c
ssdeep: 1536:io3Sey87DXUa7/732cIP9IohFnsuPI50ZoyeELE0/rmf8okfRwhpE0beVCEq/Lr:PzT+P1Tnsug5IoyeMrm8Rwhq0beoEqj
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
Assembly Version: 10.0.18362.1
InternalName: svchost.exe
FileVersion: 10.0.18362.1
CompanyName: Microsoft Corporation
LegalTrademarks:
Comments: Host Process for Windows Services
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 10.0.18362.1
FileDescription: Windows Update Assistant
OriginalFilename: svchost.exe

Zusy.240935 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.KeyloggerNET.9
CynetMalicious (score: 100)
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGen:Variant.Zusy.240935
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
Cybereasonmalicious.1fe979
CyrenW32/MSIL_Kryptik.CYI.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.VC
APEXMalicious
AvastWin32:BotX-gen [Trj]
ClamAVWin.Trojan.Razy-9778111-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.240935
MicroWorld-eScanGen:Variant.Zusy.240935
Ad-AwareGen:Variant.Zusy.240935
SophosML/PE-A + ATK/Blacknet-A
BitDefenderThetaGen:NN.ZemsilF.34796.fm0@aKWqBKo
TrendMicroBackdoor.MSIL.BLACKNET.SMDA
McAfee-GW-EditionGenericRXND-YP!A18B7CB1FE97
FireEyeGeneric.mg.a18b7cb1fe97912f
EmsisoftGen:Variant.Zusy.240935 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
MicrosoftBackdoor:MSIL/Bladabindi.G
GridinsoftRisk.CoinMiner.C.sd!yf
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
GDataGen:Variant.Zusy.240935
AhnLab-V3Malware/Gen.RL_Reputation.C4314857
McAfeeGenericRXND-YP!A18B7CB1FE97
MAXmalware (ai score=85)
VBA32CIL.StupidStealth.Heur
MalwarebytesBladabindi.Backdoor.Njrat.DDS
TrendMicro-HouseCallBackdoor.MSIL.BLACKNET.SMDA
RisingTrojan.AntiVM!1.CF63 (CLASSIC)
IkarusWorm.MSIL.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetMSIL/Agent.VC!tr
AVGWin32:BotX-gen [Trj]

How to remove Zusy.240935?

Zusy.240935 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment