Malware

What is “Zusy.311638”?

Malware Removal

The Zusy.311638 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.311638 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

How to determine Zusy.311638?


File Info:

crc32: 65BF48CE
md5: f738eb07bbe3e82645c79c1375eff839
name: upload_file
sha1: e31a6fd23b029ffe82883637d897eb2870529eee
sha256: 0675df897deb6fe05baa467fabbc8c58291b77e3ba020fb4728e5cc6f1630f9d
sha512: 766738c32dfc4c6e22e82cc3093589a629e22a5ee0652dcf276f72b56534f119424fbb98e11b63c79274c812b168b6c6b7c2198f56df588194740acbb406a04c
ssdeep: 24576:rXWT3RlwFgswMQ+BTJxyHP97v5AGGbZHb3Q4W8WZ9Ick9er5r:rXAwFg1dL5RAXb11jWnhIerV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.311638 also known as:

BkavW32.NasticodDHJ.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.311638
FireEyeGeneric.mg.f738eb07bbe3e826
CAT-QuickHealTrojan.Zusy
Qihoo-360Win32/Trojan.469
McAfeeFareit-FYT!F738EB07BBE3
CylanceUnsafe
ZillyaTrojan.Injector.Win32.764099
AegisLabTrojan.Win32.Zusy.4!c
K7AntiVirusTrojan ( 0056d0ac1 )
BitDefenderGen:Variant.Zusy.311638
K7GWTrojan ( 0056d0ac1 )
CrowdStrikewin/malicious_confidence_100% (W)
TrendMicroTROJ_GEN.R06CC0DHN20
CyrenW32/Trojan.TYHM-2043
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Kryptik.gen
AlibabaTrojan:Win32/Kryptik.c7f96c81
NANO-AntivirusTrojan.Win32.Kryptik.hsqtjn
ViRobotTrojan.Win32.Z.Injector.1259520.D
RisingTrojan.Injector!1.CB1A (CLASSIC)
Ad-AwareGen:Variant.Zusy.311638
DrWebTrojan.Siggen10.12322
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-S
SophosMal/Generic-S
IkarusTrojan.Win32.Injector
JiangminAdWare.Generic.unar
AviraTR/Kryptik.luuoz
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Kryptik
MicrosoftTrojan:Win32/Skeeyah.B!rfn
ArcabitTrojan.Zusy.D4C156
ZoneAlarmHEUR:Trojan.Win32.Kryptik.gen
GDataGen:Variant.Zusy.311638
AhnLab-V3Trojan/Win32.Agent.C4186689
Acronissuspicious
BitDefenderThetaGen:NN.ZelphiF.34252.mHW@a4EvXwfi
ALYacGen:Variant.Zusy.311638
VBA32TScope.Trojan.Delf
MalwarebytesSpyware.MassLogger
PandaTrj/CI.A
ZonerTrojan.Win32.92541
ESET-NOD32a variant of Win32/Injector.ENBV
TrendMicro-HouseCallTROJ_GEN.R06CC0DHN20
TencentWin32.Trojan.Kryptik.Ecaa
YandexTrojan.GenKryptik!
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.ENEZ!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
MaxSecureTrojan.Malware.300983.susgen

How to remove Zusy.311638?

Zusy.311638 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment