Malware

Zusy.324300 removal tips

Malware Removal

The Zusy.324300 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.324300 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Attempts to remove evidence of file being downloaded from the Internet
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Creates a hidden or system file
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Uses suspicious command line tools or Windows utilities

Related domains:

nutsystem1.bit
ns.dotbit.me
alors.deepdns.cryptostorm.net
onyx.deepdns.cryptostorm.net
ns1.any.dns.d0wn.biz
ns1.random.dns.d0wn.biz
ns2.random.dns.d0wn.biz
anyone.dnsrec.meo.ws
ist.fellig.org
civet.ziphaze.com
ns2.fr.dns.d0wn.biz
ns1.sg.dns.d0wn.biz
ns1.nl.dns.d0wn.biz
ns1.domaincoin.net
ns2.domaincoin.net

How to determine Zusy.324300?


File Info:

crc32: 118B4AD2
md5: 655fdbe7e4479a0c24337b43b42802e1
name: 655FDBE7E4479A0C24337B43B42802E1.mlw
sha1: 1864e771ea50ff21a902e5d41b0b6fb874ff93d5
sha256: 424f862a0d5cb2b2b35e022975e2c9cb230bec782a9e5e5dc92620a833092722
sha512: 88d45f2f576d2e71ffe6297cb39613dead09746c04c546f1b1ae07b25b1c26e84334a8c10dc1dae30bbe13a22d9c4382020858c93ebc0f1b9019f8bf1814e02f
ssdeep: 6144:FghDIfX26O42AbZbh1SwtmOwBRYHQmnXUi1TU8Eeqt2gF:e5Ifm6rIFOuRYwGUa9Ee82g
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.324300 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00504fe11 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader23.32524
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.S1132859
ALYacGen:Variant.Zusy.324300
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1101623
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Blocker.ccd8f7e3
K7GWTrojan ( 00504fe11 )
Cybereasonmalicious.7e4479
BaiduWin32.Trojan.Kryptik.bjc
CyrenW32/S-e2e07e9d!Eldorado
SymantecPacked.Generic.521
ESET-NOD32a variant of Win32/Kryptik.FOIB
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Malware.Mikey-9809358-0
KasperskyTrojan-Ransom.Win32.Blocker.lkck
BitDefenderGen:Variant.Zusy.324300
NANO-AntivirusTrojan.Win32.Blocker.elnwfn
ViRobotTrojan.Win32.Agent.273408.P
SUPERAntiSpywareBackdoor.Andromeda/Variant
MicroWorld-eScanGen:Variant.Zusy.324300
TencentMalware.Win32.Gencirc.114a24c9
Ad-AwareGen:Variant.Zusy.324300
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34770.qqW@ae3yQ8g
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Blocker.R002C0OFT21
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
FireEyeGeneric.mg.655fdbe7e4479a0c
EmsisoftGen:Variant.Zusy.324300 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.gjs
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1129378
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Carberp.K
AegisLabTrojan.Multi.Generic.4!c
GDataGen:Variant.Zusy.324300
AhnLab-V3Trojan/Win32.Scar.R195347
McAfeeGenericRXAZ-EZ!655FDBE7E447
MAXmalware (ai score=100)
VBA32Trojan.Bublik
MalwarebytesBackdoor.Andromeda
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_Blocker.R002C0OFT21
RisingTrojan.Kryptik!1.A8FF (CLASSIC)
YandexTrojan.GenAsa!dF+pWSQX8Dg
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.FPAL!tr
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HwkAA20C

How to remove Zusy.324300?

Zusy.324300 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment