Malware

How to remove “Zusy.288051”?

Malware Removal

The Zusy.288051 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.288051 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

launcher.nullcoreproject.net
nullcoreproject.net
www.bing.com

How to determine Zusy.288051?


File Info:

crc32: 85E4EC8A
md5: 4e77841f22749f3ed05ef55dcc9fc4f3
name: 4E77841F22749F3ED05EF55DCC9FC4F3.mlw
sha1: 325287848665553001f790b49a840ee331886746
sha256: dd2a7c65cba4cd9890d4a30ebd9b843e13ca421a4bee8bf7b393ff08b2072f0c
sha512: 0af4a04ea71f872aea9ee9225421133e32303cb2a9a66d35025b83b20727f5d769e5d9071a69ff6ca8ba26e875ff6a75027c5d8f00e6935898b49379b5cb4450
ssdeep: 768:uhHU8daRnNsYgOASaEVQjzvaA/EpOIuf:YBw3BVQj3cYIuf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.288051 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.288051
McAfeeGenericRXGO-WQ!4E77841F2274
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00527ab11 )
BitDefenderGen:Variant.Zusy.288051
K7GWTrojan ( 00527ab11 )
Cybereasonmalicious.f22749
CyrenW32/S-697fd132!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AegisLabTrojan.Win32.Generic.4!c
RisingTrojan.Invader!8.450 (TFE:1:rB2Ia4aeQRD)
Ad-AwareGen:Variant.Zusy.288051
SophosMal/Generic-S
ComodoMalware@#d2i126nfsnhq
F-SecureTrojan.TR/Vundo.Gen
McAfee-GW-EditionBehavesLike.Win32.Generic.nc
MaxSecureTrojan.Malware.300983.susgen
FireEyeGeneric.mg.4e77841f22749f3e
EmsisoftGen:Variant.Zusy.288051 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Vundo.Gen
MAXmalware (ai score=96)
Antiy-AVLTrojan/Win32.Invader
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.Zusy.D46533
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Zusy.288051
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2309462
Acronissuspicious
VBA32BScope.Trojan.Invader
ALYacGen:Variant.Zusy.288051
MalwarebytesMalware.Heuristic.1001
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Injector.EDHG
TencentWin32.Trojan.Generic.Pftn
YandexTrojan.GenAsa!A+B4FkZn3JY
IkarusTrojan.Vundo
eGambitUnsafe.AI_Score_98%
FortinetW32/Kryptik.GOIA!tr
BitDefenderThetaAI:Packer.BF0FED311F
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Zusy.288051?

Zusy.288051 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment