Malware

How to remove “Zusy.318851”?

Malware Removal

The Zusy.318851 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.318851 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.318851?


File Info:

crc32: 1FF6CE24
md5: 17d6b9bec5de846af91186d72a07ad75
name: upload_file
sha1: 21d8adb8183d8a7b299a695c4c40689884a398e5
sha256: 1215e5a32d1b0d9c445ca6fb872edd3e5d70fefcc1640dea9889a610da1a7ab2
sha512: 651aa5ba82254981b09268b141cefe8d6bfde16f62bdc9703e5c278257a22c54a45c71ffc5c574d524555e749dd4167dfb9a00de80c73175e3cb0cb53ab0d655
ssdeep: 12288:K9OMq0DYo8Ninz10A2xPX9LBdrLREIVWd2mCkmaPRr3ctBfXBkfuwQty0:B9toKinzGNLBdpEvrCkmap3cLxcuDtb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Co;;pk Softakire Corp.
InternalName:
FileVersion: 6f0
CompanyName: Brlan44lSre Co.
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 6z5.0
FileDescription:
OriginalFilename:
Translation: 0x0409 0x04e4

Zusy.318851 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.318851
CAT-QuickHealTrojan.Crypt
Qihoo-360Generic/HEUR/QVM05.1.949F.Malware.Gen
ALYacSpyware.AgentTesla
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderGen:Variant.Zusy.318851
K7GWTrojan ( 00570de21 )
K7AntiVirusTrojan ( 00570de21 )
TrendMicroTrojanSpy.Win32.FAREIT.USMANJE20
CyrenW32/Injector.XXVR-2864
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Crypt.gen
AlibabaTrojan:Win32/DelfInject.ali2000015
ViRobotTrojan.Win32.S.Infostealer.816128
RisingTrojan.Injector!8.C4 (TFE:5:7SYQkOmRBLH)
Ad-AwareGen:Variant.Zusy.318851
EmsisoftGen:Variant.Zusy.318851 (B)
ComodoMalware@#2myrez4a5gbcz
F-SecureTrojan.TR/Injector.jibfw
DrWebTrojan.PWS.Stealer.23680
InvinceaMal/Generic-S + Troj/Inject-GNZ
McAfee-GW-EditionBehavesLike.Win32.Fareit.bh
FireEyeGeneric.mg.17d6b9bec5de846a
SophosTroj/Inject-GNZ
SentinelOneDFI – Suspicious PE
WebrootW32.Malware.Gen
AviraTR/Injector.jibfw
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/LokibotCrypt.RK!MTB
ArcabitTrojan.Zusy.D4DD83
ZoneAlarmHEUR:Trojan.Win32.Crypt.gen
GDataMSIL.Trojan-Stealer.AgentTesla.F333DJ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Injector.R353185
Acronissuspicious
McAfeePWS-FCRZ!17D6B9BEC5DE
VBA32TScope.Trojan.Delf
MalwarebytesTrojan.MalPack.DLF
PandaTrj/CI.A
ZonerTrojan.Win32.96030
ESET-NOD32MSIL/Spy.Agent.AES
TrendMicro-HouseCallTrojanSpy.Win32.FAREIT.USMANJE20
IkarusTrojan.Inject
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.ETYV!tr
BitDefenderThetaGen:NN.ZelphiF.34570.XG0@aKpl2Yfi
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Zusy.318851?

Zusy.318851 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment