Malware

How to remove “Zusy.301914”?

Malware Removal

The Zusy.301914 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.301914 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Creates a hidden or system file
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
marroiq.com

How to determine Zusy.301914?


File Info:

crc32: B5B23EE5
md5: 3a26dbb6dfc0513cf46cffea6e83835a
name: billiz.exe
sha1: 2cfafa672cbb5c5a48edc45b2454998ea4332ab7
sha256: 7a178eb5af773199f14ca84ceaf1d67d8b4a615c215d04ab3c763e61e2ad7456
sha512: 87598d302f9989e2579c5860aabdf83b01701b3dd828f45b4bb2c5f0a3c5617b20d525db903c073366a2468efb2b035b86b3e54c896093c38061d5d910003910
ssdeep: 12288:9gOdoGRmJnRojvmWsNfPeU3rLXetqzaubp1xVDNjcyVw:KuoGInRoiWsJeKLXcq11hNYyVw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 20onww.fsf.org>
InternalName: m4
FileVersion: 1.4
License: This promokyleft/lesser.html.
CompanyName: Gnet>
LegalTrademarks: Gnxae,m4xae
WWW: http:/are/m4
ProductName: M
ProductVersion: 127
FileDescription: M4xorocessor
OriginalFilename: m.s2e
Translation: 0x0409 0x04e4

Zusy.301914 also known as:

MicroWorld-eScanGen:Variant.Zusy.301914
FireEyeGeneric.mg.3a26dbb6dfc0513c
Qihoo-360HEUR/QVM05.1.B703.Malware.Gen
McAfeeFareit-FSK!3A26DBB6DFC0
CylanceUnsafe
BitDefenderGen:Variant.Zusy.301914
K7GWTrojan ( 00564fdd1 )
CrowdStrikewin/malicious_confidence_70% (D)
BitDefenderThetaGen:NN.ZelphiF.34106.KG0@a4YhKjei
CyrenW32/Trojan.KIGM-3551
GDataGen:Variant.Zusy.301914
KasperskyHEUR:Trojan-PSW.Win32.Agensla.gen
APEXMalicious
TencentWin32.Backdoor.Fareit.Auto
Ad-AwareGen:Variant.Zusy.301914
SophosMal/Fareit-V
DrWebTrojan.PWS.Stealer.28391
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Fareit.hc
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Zusy.301914 (B)
SentinelOneDFI – Suspicious PE
F-ProtW32/Trojan2.QBVM
WebrootW32.Trojan.Gen
MAXmalware (ai score=86)
Endgamemalicious (high confidence)
ArcabitTrojan.Zusy.D49B5A
ZoneAlarmHEUR:Trojan-PSW.Win32.Agensla.gen
MicrosoftTrojan:Win32/Wacatac.C!ml
AhnLab-V3Suspicious/Win.Delphiless.X2059
Acronissuspicious
ALYacGen:Variant.Zusy.301914
MalwarebytesTrojan.MalPack.DLF.Generic
ESET-NOD32a variant of Win32/Injector.ELNW
RisingTrojan.Injector!8.C4 (TFE:dGZlOgW5o9imTBLjmA)
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.ELKP!tr
Cybereasonmalicious.72cbb5
Paloaltogeneric.ml

How to remove Zusy.301914?

Zusy.301914 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment