Malware

How to remove “Zusy.311814”?

Malware Removal

The Zusy.311814 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.311814 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

How to determine Zusy.311814?


File Info:

crc32: C00C352F
md5: 2172271084e5c7e1d2bf3a88698ab1eb
name: upload_file
sha1: 1e9e0da2558873f9f6368c704a46aa2dce35b0a4
sha256: 99242f3a0adf260761edec902496e2ae9c45e2488522d29d1d0df212bdd7b48a
sha512: e7069012921a64b1e92376936da4246ce4a60ed1b8cdcf16a428890bf1bf57a3aed8501be74f0f47b7a0c4d9426822b5497e292a6c34198476878ed950907fcf
ssdeep: 24576:EbOc7E3XXMa9uqBt0WmHAncunWlIG9IRREGtu+BBn5klgSyaTnCiDcii9xHjymsc:EbYnMiX53snn69xvfl
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.311814 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.311814
FireEyeGeneric.mg.2172271084e5c7e1
CAT-QuickHealTrojan.Wacatac
McAfeeFareit-FYT!2172271084E5
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Graftor.4!c
SangforMalware
K7AntiVirusTrojan ( 0056d23b1 )
BitDefenderGen:Variant.Zusy.311814
K7GWTrojan ( 0056d23b1 )
Cybereasonmalicious.255887
TrendMicroTROJ_GEN.R011C0DHO20
BitDefenderThetaGen:NN.ZelphiF.34196.cHW@aSjubnoi
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R011C0DHO20
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.Win32.Coins.gen
Ad-AwareGen:Variant.Zusy.311814
F-SecureTrojan.TR/Kryptik.xurea
DrWebTrojan.PWS.Stealer.25089
Invinceaheuristic
SentinelOneDFI – Suspicious PE
SophosMal/Generic-S
APEXMalicious
AviraTR/Kryptik.xurea
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/Skeeyah.B!rfn
ArcabitTrojan.Zusy.D4C206
ZoneAlarmHEUR:Trojan-PSW.Win32.Coins.gen
GDataGen:Variant.Zusy.311814
AhnLab-V3Suspicious/Win.Delphiless.X2094
VBA32TScope.Trojan.Delf
ALYacGen:Variant.Zusy.311814
MalwarebytesSpyware.AzorUlt
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.ENBV
RisingTrojan.Injector!1.AFE3 (CLOUD)
IkarusTrojan.Inject
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.ENBK!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.PSW.3f3

How to remove Zusy.311814?

Zusy.311814 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment