Malware

Zusy.312962 removal instruction

Malware Removal

The Zusy.312962 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.312962 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (15 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

six.skt-one.com

How to determine Zusy.312962?


File Info:

crc32: C2EF63D0
md5: 35818dc534a6cf33df349dd6c1e3da0d
name: 35818DC534A6CF33DF349DD6C1E3DA0D.mlw
sha1: 341a2c83c0c37bf8ae1271b5a9aa115db500d464
sha256: 5d727fd718012913994b35724e8e049c82a1484b4f3261f1b3b86fbf1552e4de
sha512: 7111c1382d9f7951c39ef55f91c82d0798caf3c2b8c62178f045e8f64ae26fb7934c9a9bd94cf501bd121fc8941c666477c9ee0552395dadccd23b00f3ec3364
ssdeep: 6144:RfxNZYfdqvJQhBnKNIRsB+9bz08nCFTLqVlmdVESz50o6y2/+TFX8rSLV:sd2JerViGCFqV4dOS10o6y2/+RX8s
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) Microsoft Corp. 2002-2019
InternalName: Microsoft (R) Developer Studio
FileVersion: 6.00.81.632
ProductName: Microsoft (R) Visual Studio C++
ProductVersion: 6.00.81.632
FileDescription: Microsoft (R) Developer Studio
OriginalFilename: Microsoft (R) Visual Studio
Translation: 0x0804 0x04b0

Zusy.312962 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0056ca671 )
Elasticmalicious (high confidence)
DrWebTrojan.SpyBot.776
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.312962
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan ( 0056ca671 )
Cybereasonmalicious.534a6c
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenKryptik.EPLI
APEXMalicious
AvastWin32:HacktoolX-gen [Trj]
ClamAVWin.Malware.Farfli-6824120-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.312962
NANO-AntivirusTrojan.Win32.SpyBot.hlkvgd
MicroWorld-eScanGen:Variant.Zusy.312962
TencentWin32.Trojan.Generic.Ljtx
Ad-AwareGen:Variant.Zusy.312962
F-SecureHeuristic.HEUR/AGEN.1141341
BitDefenderThetaGen:NN.ZexaF.34608.lr1@a4fzS7lb
McAfee-GW-EditionGenericRXMM-HT!35818DC534A6
FireEyeGeneric.mg.35818dc534a6cf33
EmsisoftGen:Variant.Zusy.312962 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Farfli.dnx
AviraHEUR/AGEN.1141341
Antiy-AVLTrojan[Backdoor]/Win32.Farfli
MicrosoftTrojan:Win32/Farfli.DSK!MTB
ArcabitTrojan.Zusy.D4C682
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Zusy.312962
AhnLab-V3Trojan/Win32.Farfli.R353793
McAfeeGenericRXMM-HT!35818DC534A6
MAXmalware (ai score=89)
MalwarebytesGeneric.Trojan.Malicious.DDS
RisingBackdoor.Farfli!8.B4 (TFE:dGZlOgVT6yiFPoxqrw)
IkarusTrojan.Win32.Krypt
FortinetW32/GenKryptik.EOZH!tr
AVGWin32:HacktoolX-gen [Trj]
Qihoo-360Generic/Trojan.7f1

How to remove Zusy.312962?

Zusy.312962 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment