Malware

Zusy.310063 (B) removal instruction

Malware Removal

The Zusy.310063 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.310063 (B) virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to mimic the file extension of a PDF document by having ‘pdf’ in the file name.
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Creates a hidden or system file
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

colbaservices.cf

How to determine Zusy.310063 (B)?


File Info:

crc32: DC80F82C
md5: 4d4e9ed4e9e15ad2f1b33a816c4688eb
name: file-000444_pdf.exe
sha1: 8cb2ea36b78d8f33e4cba43cdf6049f3b6065ef8
sha256: 971bd34392ee895a7eecf6b1dd6b784aa28d17d744c0ff54b192c96a03a58bdb
sha512: 862501b18a265eb9d7fd26f8891be43d665f015da8f4637123860887d34c515ff9596689cdb102791232917f385bb0b1916f7b5bc181b42109a8e1fb5d77a70d
ssdeep: 12288:bYM1AJ/Y1Nda4YainuE5Ou1tFw0uKHFYbaEWe6Bt1pQepKOwrs92:cWl1K4mOu9wsqaEpK1SOn92
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.310063 (B) also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.310063
FireEyeGeneric.mg.4d4e9ed4e9e15ad2
CAT-QuickHealTrojan.Wacatac
McAfeeFareit-FPQ!4D4E9ED4E9E1
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0056b5001 )
BitDefenderGen:Variant.Zusy.310063
K7GWTrojan ( 0056b5001 )
Cybereasonmalicious.6b78d8
TrendMicroTROJ_GEN.R002C0WGS20
F-ProtW32/Injector.JGM
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Kryptik.gen
AlibabaTrojan:Win32/DelfInject.ali2000015
AegisLabTrojan.Win32.Zusy.4!c
Ad-AwareGen:Variant.Zusy.310063
EmsisoftGen:Variant.Zusy.310063 (B)
F-SecureTrojan.TR/Injector.wzirq
DrWebBackDoor.SpyBotNET.25
Invinceaheuristic
FortinetW32/EMTN!tr
SophosTroj/Fareit-KZN
SentinelOneDFI – Suspicious PE
CyrenW32/Injector.YSIV-6452
AviraTR/Injector.wzirq
MAXmalware (ai score=84)
ArcabitTrojan.Zusy.D4BB2F
ZoneAlarmHEUR:Trojan.Win32.Kryptik.gen
MicrosoftTrojan:Win32/FormBook.DE!MTB
CynetMalicious (score: 90)
AhnLab-V3Trojan/Win32.Injector.C4170954
Acronissuspicious
VBA32TScope.Trojan.Delf
ALYacGen:Variant.Zusy.310063
MalwarebytesSpyware.PasswordStealer
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.EMTN
TrendMicro-HouseCallTROJ_GEN.R002C0WGS20
RisingTrojan.Injector!1.C99D (CLOUD)
IkarusTrojan.Inject
MaxSecureTrojan.Malware.300983.susgen
GDataGen:Variant.Zusy.310063
BitDefenderThetaGen:NN.ZelphiF.34144.MGW@a4DVOYfi
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Generic/HEUR/QVM05.1.DE5B.Malware.Gen

How to remove Zusy.310063 (B)?

Zusy.310063 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment