Malware

Zusy.258036 (file analysis)

Malware Removal

The Zusy.258036 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.258036 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Performs some HTTP requests

Related domains:

s3.amazonaws.com
ocsp.digicert.com
crl3.digicert.com
crl4.digicert.com

How to determine Zusy.258036?


File Info:

crc32: 7BB048D9
md5: 5b03936a7f59092e5ab0ce7a3ac00c4d
name: 5B03936A7F59092E5AB0CE7A3AC00C4D.mlw
sha1: c429dbdcfeff0627d5d8ccf41b8d345431c4c900
sha256: 1dec618c18b7867b6a1fbcd6e33df8ac7bfa2d171fb5a652326eea7156e8fa5a
sha512: 58be7b3359302082151a51942c5f78f9e2a47a75c0076a020e0c4e0149f09234fd159662aca15d3af6ecfbfd1b5927a2bf45cd5309d17cb51997df8d2bb99448
ssdeep: 24576:IHNoucCOX3KIVIY9iV3zhxD+SGqTCrelc2YfspBqSjitFyNFa0kAEp7tUtf/Tye:UMCTyil60p0SjICF4+/TJVT4zRnoNi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.258036 also known as:

K7AntiVirusTrojan-Downloader ( 005105461 )
LionicTrojan.Multi.Generic.4!c
CynetMalicious (score: 99)
ALYacGen:Variant.Zusy.258036
CylanceUnsafe
ZillyaDownloader.Delf.Win32.56400
SangforTrojan.Win32.Delf.kvgu
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan-Downloader ( 005105461 )
Cybereasonmalicious.a7f590
CyrenW32/Banload.DE.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Banload.XZH
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Downloader.Win32.Delf.kvgu
BitDefenderGen:Variant.Zusy.258036
NANO-AntivirusTrojan.Win32.Banload.ezaspa
MicroWorld-eScanGen:Variant.Zusy.258036
TencentWin32.Trojan-downloader.Delf.Suxn
Ad-AwareGen:Variant.Zusy.258036
SophosMal/Generic-S
ComodoMalware@#1x8h27da8pa6k
BitDefenderThetaAI:Packer.8754FC4721
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_BANLOAD.SM0
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
FireEyeGeneric.mg.5b03936a7f59092e
EmsisoftGen:Variant.Zusy.258036 (B)
JiangminTrojanDownloader.Delf.atcf
AviraTR/Downloader.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.2510C87
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Occamy.C1D
GDataGen:Variant.Zusy.258036
McAfeeGenericRXBV-ZG!5B03936A7F59
MAXmalware (ai score=98)
VBA32BScope.TrojanDownloader.Delf
PandaTrj/GdSda.A
TrendMicro-HouseCallTSPY_BANLOAD.SM0
RisingTrojan.Generic@ML.81 (RDML:M+hOF3oCfOwKODUJwMl5sg)
YandexTrojan.DL.Delf!i2qNgDgw0Yw
IkarusTrojan-Downloader.Win32.Banload
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Banload.XZH!tr.dldr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Zusy.258036?

Zusy.258036 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment