Malware

Zusy.286798 removal

Malware Removal

The Zusy.286798 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.286798 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.286798?


File Info:

crc32: 431BF5B0
md5: 71e72689a1e6750ec5dcf6a6f0cf3edb
name: 71E72689A1E6750EC5DCF6A6F0CF3EDB.mlw
sha1: 65fb6b5017c45b6995b090a8ac429162c9853497
sha256: 204181721040564d598cf90b7fbf3975f55b6bcba6187f5916431995eb57aad1
sha512: 6cb99745293972f938144bac5e649d0f7d98823e28fbfcfc9b27e0dbd3b2102771ca97ea8e3c1510e73fcc7c078c6d4c54643c3faf96ad3633f4aa38a3f0422b
ssdeep: 6144:XAi9AhAaBTF6lqXL5ENquvvPea1rmV1HPrW44z:QWAhAyTFTLHuv3RrmV1HPK4
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Zusy.286798 also known as:

K7AntiVirusTrojan ( 005208091 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.19347
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.286798
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Kryptik.d6679ddf
K7GWTrojan ( 005208091 )
Cybereasonmalicious.9a1e67
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.NCB
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Trojan.Zbot-9812755-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.286798
NANO-AntivirusTrojan.Win32.Stealer.eymxhl
MicroWorld-eScanGen:Variant.Zusy.286798
TencentWin32.Trojan.Generic.Aiih
Ad-AwareGen:Variant.Zusy.286798
SophosML/PE-A
ComodoMalware@#2zu1wfwe1tuuc
BitDefenderThetaGen:NN.ZemsilF.34294.rmW@aOCG!mce
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_NEGASTEAL.SME
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.71e72689a1e6750e
EmsisoftGen:Variant.Zusy.286798 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.bzojg
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1102026
Antiy-AVLTrojan/Generic.ASMalwS.24C0D0A
MicrosoftTrojan:Win32/Dynamer!rfn
SUPERAntiSpywareTrojan.Agent/Gen-Injector
GDataGen:Variant.Zusy.286798
AhnLab-V3Trojan/Win32.Upatre.C2420326
Acronissuspicious
McAfeePacked-FAU!71E72689A1E6
MAXmalware (ai score=99)
VBA32TrojanPSW.Stealer
MalwarebytesSpyware.AgentTesla.MSIL.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTSPY_NEGASTEAL.SME
YandexTrojan.Agent!oGqDMPdjCqk
IkarusTrojan.Crypter
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/GenKryptik.BRJF!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Zusy.286798?

Zusy.286798 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment