Malware

Zusy.310062 (file analysis)

Malware Removal

The Zusy.310062 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.310062 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Attempts to mimic the file extension of a PDF document by having ‘pdf’ in the file name.
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.310062?


File Info:

crc32: 91082A50
md5: ada5beecde7f9234cfea4e0654758f9e
name: PO7883.pdf.exe
sha1: 6d9679f46a29b18d3caadb9217b0fa1790c42578
sha256: 391bd050efa8e5d02a1d1a5bb174374efce434f2457fdb0ca4c26f92341e4fa5
sha512: eca76675eb7411c129891ad2dcc87e9b65a67a15fe0d75856737e7bd4d5ebb5b56ffb4836d31764e2663b34e06600a04642c84fec1e6ea2207443d1704eeeee9
ssdeep: 24576:VWl1K4mOu9wsqaEpXtmxS04UvcRrhlMJSdby4TtBEX6jCMi:V2y7EpSS04gc5h7b4XyCMi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.310062 also known as:

BkavW32.AIDetectVM.malware1
FireEyeGeneric.mg.ada5beecde7f9234
McAfeeArtemis!ADA5BEECDE7F
MalwarebytesSpyware.PasswordStealer
SangforMalware
BitDefenderGen:Variant.Zusy.310062
K7GWTrojan ( 0056b5001 )
Cybereasonmalicious.46a29b
Invinceaheuristic
APEXMalicious
Paloaltogeneric.ml
GDataGen:Variant.Zusy.310062
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/DelfInject.ali2000015
MicroWorld-eScanGen:Variant.Zusy.310062
Ad-AwareGen:Variant.Zusy.310062
F-SecureTrojan.TR/Injector.mextw
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Zusy.310062 (B)
IkarusWin32.Outbreak
AviraTR/Injector.mextw
MAXmalware (ai score=81)
Endgamemalicious (high confidence)
ArcabitTrojan.Zusy.D4BB2E
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Wacatac.C!ml
Acronissuspicious
BitDefenderThetaGen:NN.ZelphiF.34138.gHW@aCSavsfi
CylanceUnsafe
ESET-NOD32a variant of Win32/Injector.EMTN
RisingTrojan.Injector!1.C97E (CLASSIC)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/EMTN!tr
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/QVM05.1.DC98.Malware.Gen

How to remove Zusy.310062?

Zusy.310062 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment