Malware

Zusy.305852 information

Malware Removal

The Zusy.305852 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.305852 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Zusy.305852?


File Info:

crc32: ADA683FA
md5: ed486298cddbd2de5fad630ecfa09132
name: tmpr2g7_77p
sha1: fae9d956e038f3ecc3acd4bdfb277f1bc9277879
sha256: b9c294da9b99a00f8704849b38f9fcc82513e750d1933c33ea8912a00babeb61
sha512: d036de26374ce449a3eb7d7baee5c5221d672eea935b29405a7ea4628b753bd88144c1a0bb500dc1a374d8a623297101d06ef4133d68d1b80aec0eb2ab46cb3d
ssdeep: 12288:BUeVJlfbhJTd58SYzh5uzMIts6DDt9USu0NMfMtQ:FJTdKSMGsQt2WNMM
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: RoseThose xa9 2017
InternalName: Art woman
FileVersion: 2.1.3.996
CompanyName: Win ToCase
ProductName: Horse.dll
ProductVersion: 2.1.3.996
FileDescription: RoseThose
Translation: 0x0409 0x04b0

Zusy.305852 also known as:

MicroWorld-eScanGen:Variant.Zusy.305852
FireEyeGeneric.mg.ed486298cddbd2de
Qihoo-360HEUR/QVM40.1.EC08.Malware.Gen
McAfeeGenericRXKY-JQ!ED486298CDDB
VIPRETrojan.Win32.Generic!BT
BitDefenderGen:Variant.Zusy.305852
K7GWTrojan ( 005669021 )
K7AntiVirusTrojan ( 005669021 )
F-ProtW32/S-50dbd228!Eldorado
AvastWin32:Trojan-gen
GDataGen:Variant.Zusy.305852
KasperskyTrojan-Banker.Win32.Cridex.obk
RisingTrojan.GenKryptik!8.AA55 (C64:YzY0OrmWw1Wdh5Rj)
EmsisoftGen:Variant.Zusy.305852 (B)
ComodoTrojWare.Win32.Kryptik.HACE@8so3pu
F-SecureTrojan.TR/Kryptik.vxpvh
McAfee-GW-EditionGenericRXKY-JQ!ED486298CDDB
SophosTroj/Agent-BESY
IkarusTrojan.Win32.Krypt
CyrenW32/S-50dbd228!Eldorado
JiangminTrojan.Banker.Cridex.zq
AviraTR/Kryptik.vxpvh
MAXmalware (ai score=86)
Antiy-AVLTrojan[Banker]/Win32.Cridex
ArcabitTrojan.Zusy.D4AABC
ZoneAlarmTrojan-Banker.Win32.Cridex.obk
MicrosoftTrojan:Win32/Zloader.ARJ!MTB
CynetMalicious (score: 85)
AhnLab-V3Trojan/Win32.Agent.C4117784
VBA32TrojanBanker.Cridex
ALYacGen:Variant.Zusy.305852
Ad-AwareGen:Variant.Zusy.305852
MalwarebytesTrojan.Crypt
ESET-NOD32a variant of Win32/Kryptik.HDZG
TencentMalware.Win32.Gencirc.10cdd2f1
YandexTrojan.GenKryptik!
SentinelOneDFI – Suspicious PE
FortinetW32/Agent.BEVR!tr
BitDefenderThetaGen:NN.ZedlaF.34128.Eu8@aOuyBrii
AVGWin32:Trojan-gen
MaxSecureTrojan.Malware.102058694.susgen

How to remove Zusy.305852?

Zusy.305852 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment