Malware

Zusy.307485 removal instruction

Malware Removal

The Zusy.307485 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.307485 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
static.17.249.201.195.clients.your-server.de

How to determine Zusy.307485?


File Info:

crc32: 9B903CBF
md5: b22d47a4d6a29ec6a826b36d63235033
name: B22D47A4D6A29EC6A826B36D63235033.mlw
sha1: a80c0e1866b3aad290034cbba0364d74601a83d4
sha256: 24c5faf1541c75d09691d5dd5a4cbd61f7750f814abd5cd996dd7885db2e8926
sha512: 16b206ac30ea998a4b66843953c33c0353f5bb29651bb5da840e40121bb10c82fb745ffb45c953bc0c4c4ec55f731a55e5e4ba5e1839ae723f63de889b651e32
ssdeep: 49152:JAlxBOFdb14702+tdQv6PAL9xUQk+wAT6vcO4zsAQwnN5qGuwn64TcHfEOQ13lu:ixczbOJ8Qt9xUt5A2vcOJAtxp6rm3O
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 2005-2018 MODJO. All rights reserved.
FileVersion: 10, 2, 0, 6526
CompanyName: MODJO
ProductName: MODJO Internet Security
ProductVersion: 10, 2, 0, 6526
FileDescription: MODJO Internet Security
Translation: 0x0409 0x04e4

Zusy.307485 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0053e8521 )
LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.SelfdelPMF.S4247483
ALYacGen:Variant.Zusy.307485
CylanceUnsafe
ZillyaTrojan.Ekstak.Win32.14437
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win32/Selfdel.49199e4a
K7GWTrojan ( 0053e8521 )
Cybereasonmalicious.4d6a29
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GMIQ
APEXMalicious
AvastWin32:ICLoader-X [Adw]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.307485
NANO-AntivirusTrojan.Win32.InstallCube.fjvfss
MicroWorld-eScanGen:Variant.Zusy.307485
TencentWin32.Trojan.Generic.Pbyr
Ad-AwareGen:Variant.Zusy.307485
SophosMal/Generic-S
ComodoApplication.Win32.ICLoader.GS@84429a
BitDefenderThetaGen:NN.ZexaF.34266.@t0@a4Te5xki
McAfee-GW-EditionBehavesLike.Win32.Generic.rc
FireEyeGeneric.mg.b22d47a4d6a29ec6
EmsisoftGen:Variant.Zusy.307485 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/ICLoader.Gen8
MicrosoftTrojan:Win32/Selfdel.B
GDataGen:Variant.Zusy.307485
AhnLab-V3PUP/Win32.FileTour.R242805
Acronissuspicious
McAfeePacked-FME!B22D47A4D6A2
MAXmalware (ai score=100)
VBA32BScope.Trojan.Ekstak
MalwarebytesAdware.Agent
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.GenAsa!eF6jmCHgM/4
IkarusPUA.ICLoader
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:ICLoader-X [Adw]
Paloaltogeneric.ml

How to remove Zusy.307485?

Zusy.307485 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment