Malware

Zusy.270584 removal guide

Malware Removal

The Zusy.270584 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.270584 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • A process created a hidden window
  • Unconventionial language used in binary resources: Arabic (Yemen)
  • Executed a process and injected code into it, probably while unpacking
  • Queries information on disks for anti-virtualization via Device Information APIs
  • Deletes its original binary from disk
  • Code injection with CreateRemoteThread in a remote process
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
buy1.honeycat.org
buy1.pqrqtaz.ru
buy1.quwkbin.ru
buy1.rkbupij.ru
buy1.pcqmayq.ru
buy1.mmuliwe.ru
buy1.stoizji.ru
buy1.sfdfrhh.ru
buy1.ynciazz.ru
buy1.mkglhnw.ru
buy1.njeeili.ru
buy1.dldzeoo.ru
buy1.tkbiqjq.ru
buy1.uenosbl.ru
buy1.faayshc.ru
buy1.nttfazc.ru
buy1.nfwsyog.ru
buy1.uyfusxm.ru
buy1.hxkclwx.ru
buy1.zgoysam.ru
buy1.xtwbsox.ru
buy1.dnfojik.ru
buy1.zwifdqa.ru
buy1.dnnewrt.ru
buy1.reduttg.ru
buy1.syyxnmj.ru
buy1.dkqhmbi.ru
buy1.cxxhtmb.ru
buy1.xsgprgh.ru
buy1.bmazlky.ru
buy1.yunzkpy.ru
buy1.bthmzsp.ru
buy1.ypuyhme.ru
buy1.imnlqpw.ru
buy1.scrilbw.ru
buy1.uzbserc.ru
buy1.nosawck.ru
buy1.manjbkx.ru
buy1.mwuzynk.ru
buy1.ybrekcl.ru
buy1.byosnwr.ru
buy1.yzsshlc.ru
buy1.woztxhd.ru
buy1.egrsdno.ru
buy1.dyqzunc.ru
buy1.pqkgtin.ru
buy1.tbsnaoq.ru
buy1.yyeytoh.ru
buy1.jzwhkrf.ru

How to determine Zusy.270584?


File Info:

crc32: F9194B71
md5: 60fe7fe37a667a83446974349e8a552d
name: 60FE7FE37A667A83446974349E8A552D.mlw
sha1: 0ace237835f9a4e890e6dc265ad0ed5f91726d53
sha256: cf8fdb8320ec2a69d53e5ec99d3669b9f839d8a0e97efbc39e77d46ff4ca9a33
sha512: 0e2fb3835b4f0cf8cc0c738ff54602c5db46ab28f75d6489c59e79f7695d2f680d73c7b497526d8f0c9c1b69f6621f34379b518cca8ae4c6d85dfbecb2507366
ssdeep: 6144:4tb7yDeBGv1baMOXYDotNLJgYdtJL7p7oCPpJgOdiGiBJ:CPGeAvMaDotNj37p7zpaOdiGiBJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.270584 also known as:

BkavW32.TiusegLTF.Trojan
K7AntiVirusTrojan ( 0051ac211 )
MicroWorld-eScanGen:Variant.Zusy.270584
CAT-QuickHealBackdoor.Androm
ALYacGen:Variant.Zusy.270584
CylanceUnsafe
CrowdStrikemalicious_confidence_100% (D)
K7GWTrojan ( 0051ac211 )
Cybereasonmalicious.37a667
TrendMicroTROJ_KHALESI.SMALY
NANO-AntivirusVirus.Win32.Gen.ccmw
CyrenW32/Trojan.CCVO-0276
SymantecTrojan.Gen
ESET-NOD32a variant of Win32/Injector.DYZG
ZonerTrojanAgent.Generic
AvastWin32:Generic-UU [Trj]
ClamAVWin.Trojan.Agent-6407201-0
GDataWin32.Trojan.Khalesi.B
KasperskyHEUR:Trojan.Win32.Khalesi.gen
BitDefenderGen:Variant.Zusy.270584
ViRobotTrojan.Win32.Agent.267776.AC
TencentWin32.Backdoor.Androm.Wpjy
Ad-AwareGen:Variant.Zusy.270584
SophosMal/Generic-S
F-SecureGen:Variant.Zusy.270584
DrWebTrojan.Packed2.40557
ZillyaTrojan.Zusy.Win32.18
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.fh
EmsisoftGen:Variant.Zusy.270584 (B)
SentinelOnestatic engine – malicious
Endgamemalicious (high confidence)
WebrootTrojan.Khalesi.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojan:Win32/CryptInject
JiangminBackdoor.Androm.vnk
ArcabitTrojan.Zusy.D420F8
AegisLabBackdoor.W32.Androm.tp4O
ZoneAlarmHEUR:Trojan.Win32.Khalesi.gen
AhnLab-V3Trojan/Win32.MDA.R221226
McAfeePacked-XB!60FE7FE37A66
MAXmalware (ai score=99)
VBA32Trojan.Khalesi
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_KHALESI.SMALY
RisingDropper.Generic!8.35E (CLOUD)
YandexBackdoor.Androm!jxA61fGhYGU
IkarusTrojan.Inject4
FortinetW32/GenKryptik.ARNZ!tr
AVGWin32:Generic-UU [Trj]
Paloaltogeneric.ml
Qihoo-360HEUR/QVM10.1.095A.Malware.Gen

How to remove Zusy.270584?

Zusy.270584 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment