Malware

Zusy.318658 (B) removal

Malware Removal

The Zusy.318658 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.318658 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.318658 (B)?


File Info:

crc32: E68F9395
md5: 3d67bc919f22cb4c9d1594f3e9fb1e30
name: 3D67BC919F22CB4C9D1594F3E9FB1E30.mlw
sha1: 18239408b2dee32771a3a6effcb7a27784f82efa
sha256: e545a53550ec09fa230ebf953372e51e9ff234093a1eef7d788f985ea4b0af4c
sha512: 3fcdad8c4af4819612651b7bbd6f6e9f53bba9c38ecbf4c1e9486edcc813aff309de6d058d9a726d3f981818c26945d66e96531d90a2a23d8d0f5ebfc706c502
ssdeep: 24576:cMM18ulasj4DiAX7tKtFwrFC5EUnfBbWDkIAH7R74I33gbtD:fuPF57JbX7F4x
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: NCT Company Ltd. Copyright 1999 - 2003
InternalName: NCTAudioCompress2
FileVersion: 2,5,1,182
CompanyName: NCT Company Ltd.
LegalTrademarks: NCT Company Ltd.
ProductName: NCTAudioCompress2 Module
ProductVersion: 2,5,1,182
FileDescription: NCTAudioCompress2 ActiveX DLL
OriginalFilename: NCTAudioCompress2.DLL
Translation: 0x0409 0x04b0

Zusy.318658 (B) also known as:

K7AntiVirusTrojan ( 0056252b1 )
LionicTrojan.Win32.Staser.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen9.22670
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.318658
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win32/Staser.ae340c75
K7GWTrojan ( 0056252b1 )
Cybereasonmalicious.19f22c
CyrenW32/Agent.BXX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HHUB
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
ClamAVWin.Packed.Adrozek-9811562-0
BitDefenderGen:Variant.Zusy.318658
NANO-AntivirusTrojan.Win32.Staser.hzrbra
MicroWorld-eScanGen:Variant.Zusy.318658
Ad-AwareGen:Variant.Zusy.318658
SophosTroj/Agent-BEQV
BitDefenderThetaGen:NN.ZexaF.34294.lv0@ai96VBij
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.3d67bc919f22cb4c
EmsisoftGen:Variant.Zusy.318658 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Staser.iew
AviraTR/Crypt.Agent.nouql
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.30F496F
MicrosoftBrowserModifier:Win32/Adrozek
SUPERAntiSpywareTrojan.Agent/Gen-Staser
GDataGen:Variant.Zusy.318658
AhnLab-V3PUP/Win32.ICLoader.R353041
Acronissuspicious
McAfeeGenericRXMG-FV!3D67BC919F22
MAXmalware (ai score=81)
VBA32BScope.Trojan.CryptInject
MalwarebytesAdware.DownloadAssistant
PandaTrj/GdSda.A
RisingTrojan.Kryptik!1.AA23 (CLASSIC)
YandexTrojan.Staser!E/ewIPrLEKg
IkarusPUA.ICLoader
MaxSecureTrojan.Malware.73802172.susgen
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareX-gen [Adw]

How to remove Zusy.318658 (B)?

Zusy.318658 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment