Malware

About “Zusy.307425” infection

Malware Removal

The Zusy.307425 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.307425 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

moolfircineper.online

How to determine Zusy.307425?


File Info:

crc32: C278A9D9
md5: e890118322db2ed1cb410712f19f9854
name: E890118322DB2ED1CB410712F19F9854.mlw
sha1: d1804add5abf8dcfd6aca1fe42fc8af58a2b3eb7
sha256: 92047b4b6541b78991154073e2d3f20599878321d2b0de4877fcf411938e48d3
sha512: 510ce9b85eeca42d56ca0b897a4d9ad6a864c7b51acf8329681d392c47a6363535c040dc1fdc376d49519be087227c48c39b5fc56fd3b8a0246dcef1431f8719
ssdeep: 49152:NTPt1+EpfGHsXZvsAhq7oAQ7wPROyCIIzCqIPcn:5lI8GMX9thqsdiAyC7zDn
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04e4

Zusy.307425 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.307425
FireEyeGeneric.mg.e890118322db2ed1
McAfeeGenericRXAA-FA!E890118322DB
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderGen:Variant.Zusy.307425
K7GWTrojan ( 0056252b1 )
K7AntiVirusTrojan ( 0056252b1 )
CyrenW32/Kryptik.BWG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HAYM
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Downloader.Win32.Razy.vho
AlibabaTrojanDownloader:Win32/ICLoader.18743266
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
Ad-AwareGen:Variant.Zusy.307425
SophosMal/Generic-R + Troj/Agent-BEQV
ComodoMalware@#36rawwtb3xi90
F-SecureHeuristic.HEUR/AGEN.1139293
DrWebTrojan.PWS.Stealer.28354
TrendMicroTROJ_GEN.R03BC0DB121
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
EmsisoftGen:Variant.Zusy.307425 (B)
SentinelOneStatic AI – Suspicious PE – Adware
AviraHEUR/AGEN.1139293
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftBrowserModifier:Win32/Adrozek
ArcabitTrojan.Zusy.D4B0E1
AhnLab-V3PUP/Win32.Bundler.R341395
ZoneAlarmHEUR:Trojan-Downloader.Win32.Razy.vho
GDataWin32.Trojan.PSE.186HUR6
ALYacGen:Variant.Zusy.307425
MalwarebytesAdware.Agent.KHM.Generic
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DB121
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HAYM!tr
AVGWin32:AdwareX-gen [Adw]

How to remove Zusy.307425?

Zusy.307425 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment