Malware

Zusy.307818 (B) removal

Malware Removal

The Zusy.307818 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.307818 (B) virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Hebrew
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

www.ip-adress.com

How to determine Zusy.307818 (B)?


File Info:

crc32: 5FBB8A56
md5: 45fc4c29690eb03a5f82e198d5891bd1
name: 5555555.png
sha1: 8da72435d3c4fbbd448d8c66e0ffecd7e337ed96
sha256: 0ea34132d126f10d6e9fc6d1c4057b8d63542e063012e78dd1db3857ad3ae3aa
sha512: 30c2cb3489b26637530bae3fa20e6ad326664c9808e2ab161e67d79f8b10250ac10ad82a5f15eead191f6dc8499f2b6118c831eb051d8ddb9ce3a4d3e11241d4
ssdeep: 12288:2jCll3pc7zt7G7A727Y5zaPJUaAPSFcz74S1KzPp4DP6Nh:2jCll3IOUjKB5PyDM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2009 - 2011 Nir Sofer
InternalName: WhatInStartup
FileVersion: 1.33
CompanyName: NirSoft
ProductName: WhatInStartup
ProductVersion: 1.33
FileDescription: WhatInStartup
OriginalFilename: WhatInStartup.exe
Translation: 0x0409 0x04b0

Zusy.307818 (B) also known as:

BkavHW32.Packed.
MicroWorld-eScanGen:Variant.Cerbu.73397
FireEyeGeneric.mg.45fc4c29690eb03a
CylanceUnsafe
SangforMalware
BitDefenderGen:Variant.Zusy.307818
Cybereasonmalicious.5d3c4f
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataGen:Variant.Cerbu.73397
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Zusy.307818 (B)
VIPRELooksLike.Win32.Dridex.c (v)
Trapminemalicious.high.ml.score
SophosMal/EncPk-APV
MAXmalware (ai score=82)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
VBA32BScope.TrojanRansom.Shade
Ad-AwareGen:Variant.Cerbu.73397
ESET-NOD32a variant of Win32/Kryptik.HELU
RisingTrojan.Kryptik!1.C745 (RDMK:cmRtazo5TLyCOxsur0JeFkCqnH/D)
SentinelOneDFI – Malicious PE
eGambitPE.Heur.InvalidSig
BitDefenderThetaGen:NN.ZexaF.34130.FK1@aOicj8iO
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM19.1.31DB.Malware.Gen

How to remove Zusy.307818 (B)?

Zusy.307818 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment