Malware

Zusy.309802 (B) removal instruction

Malware Removal

The Zusy.309802 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.309802 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.309802 (B)?


File Info:

crc32: DBB5940A
md5: 49f244be74518183470939814fc64cd7
name: 130avisors.exe
sha1: 3aad23113e364cd3a2d487c11bd7cdca9427bf6e
sha256: ff770de144628dbb7931d252cedc942b61852f3957312ec8d2e8a4776314ee20
sha512: 6b599cae85721e61501cc624b11d5720b148cb301d46fb1079b0cba4c99f952a38e8cd5baadbbfdf2ede742caeaafb2b7cb53afa6cc689aedeca5f0ab54824e7
ssdeep: 6144:T4p06YZxFrAfp9NlOvTULvRf71SWZsYM+VX+bUOGcLZo3nU:UxYL2fpsvUfhxvVX+9Z0U
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2002
InternalName: NetBIOS Enumerater
FileVersion: 1, 0, 1, 2
CompanyName: Camelott GmbH
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Camelott GmbH NetBIOS Enumerater
SpecialBuild:
ProductVersion: 1, 0, 1, 2
FileDescription: NetBIOS Enumerater
OriginalFilename: NetBIOS Enumerater.exe
Translation: 0x0407 0x04b0

Zusy.309802 (B) also known as:

MicroWorld-eScanGen:Variant.Zusy.309802
FireEyeGeneric.mg.49f244be74518183
CAT-QuickHealTrojan.IGENERIC
ALYacGen:Variant.Zusy.309802
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0056ae9f1 )
BitDefenderGen:Variant.Zusy.309802
K7GWTrojan ( 0056ae9f1 )
F-ProtW32/Kryptik.BQQ.gen!Eldorado
ESET-NOD32Win32/TrickBot.DI
APEXMalicious
KasperskyHEUR:Trojan.Win32.Zenpak.vho
NANO-AntivirusTrojan.Win32.Zenpak.horwtu
RisingMalware.Heuristic!ET#89% (RDMK:cmRtazrKcYPLOAlun07FGgVrXDtd)
Ad-AwareGen:Variant.Zusy.309802
F-SecureTrojan.TR/AD.TrickBot.dbiii
DrWebTrojan.Packed.140
Invinceaheuristic
EmsisoftGen:Variant.Zusy.309802 (B)
IkarusTrojan-Banker.TrickBot
CyrenW32/Kryptik.BQQ.gen!Eldorado
AviraTR/AD.TrickBot.dbiii
FortinetW32/Zenpak.APEI!tr
Antiy-AVLTrojan/Win32.Zenpak
ArcabitTrojan.Zusy.D4BA2A
AhnLab-V3Trojan/Win32.Trickbot.C4166494
ZoneAlarmHEUR:Trojan.Win32.Zenpak.vho
MicrosoftTrojan:Win32/Trickbot.MX!MTB
CynetMalicious (score: 85)
McAfeeGenericRXAA-AA!49F244BE7451
MAXmalware (ai score=89)
VBA32BScope.Backdoor.Emotet
MalwarebytesTrojan.MalPack
SentinelOneDFI – Malicious PE
GDataGen:Variant.Zusy.309802
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360HEUR/QVM09.0.335F.Malware.Gen

How to remove Zusy.309802 (B)?

Zusy.309802 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment