Malware

Zusy.326614 (file analysis)

Malware Removal

The Zusy.326614 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.326614 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks for anti-virtualization via Device Information APIs
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
ssl.65financial.com

How to determine Zusy.326614?


File Info:

crc32: 55472DF0
md5: b73f42c6b959e7576dcbf7c2f1bf5aae
name: B73F42C6B959E7576DCBF7C2F1BF5AAE.mlw
sha1: d57ed4aa9315b66bb156814841751482e6ed8519
sha256: 04c6f1f37367fe790f769f80889bb9bf63270545f82c4ae4f26dae4b71853258
sha512: c5c9a073e589c09242b0c650ca71064bd800deb8dbee6f8a004e8c32d30dc34fbcc8b5053afba0e94fb58feec888d6074a1b8506e706168cac2c1f132a45de51
ssdeep: 3072:zWJlRJCOVZ3lNLFyQQXemq64OROJnidFej1rzyEfzYMoBuwPGPEEhg5SCBhnRgu:PZcqUfBOM9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.326614 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00515aa21 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Sphinx.2
ClamAVWin.Ransomware.Cerber-6162245-0
ALYacGen:Variant.Zusy.326614
MalwarebytesRansom.Cerber
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005057ac1 )
Cybereasonmalicious.6b959e
BaiduWin32.Trojan.Kryptik.bjk
CyrenW32/S-1ecee49a!Eldorado
SymantecPacked.Generic.493
ESET-NOD32a variant of Win32/Kryptik.FOKX
APEXMalicious
AvastWin32:Filecoder-AY [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Ransom.Win32.Zerber.vho
BitDefenderGen:Variant.Zusy.326614
NANO-AntivirusTrojan.Win32.Sphinx.evricw
MicroWorld-eScanGen:Variant.Zusy.326614
TencentMalware.Win32.Gencirc.10b6738e
Ad-AwareGen:Variant.Zusy.326614
ComodoTrojWare.Win32.Crypt.C@7vajd0
BitDefenderThetaGen:NN.ZexaF.34142.kmW@aWbGoDk
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.SM37
McAfee-GW-EditionBehavesLike.Win32.Ransomware.ch
FireEyeGeneric.mg.b73f42c6b959e757
EmsisoftGen:Variant.Zusy.326614 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.btaxg
AviraHEUR/AGEN.1116787
Antiy-AVLTrojan/Generic.ASMalwS.22E2250
MicrosoftTrojanSpy:Win32/Ursnif.HX
SUPERAntiSpywareRansom.Spora/Variant
GDataGen:Variant.Zusy.326614
AhnLab-V3Trojan/Win32.Spora.R195429
Acronissuspicious
McAfeeRansomware-FMJ!B73F42C6B959
MAXmalware (ai score=99)
VBA32BScope.TrojanPSW.Sphinx
PandaTrj/CI.A
TrendMicro-HouseCallRansom_CERBER.SM37
RisingTrojan.Generic@ML.100 (RDML:1Bfe0DxOH+1aQ+bSPlvSmQ)
YandexTrojan.GenAsa!a6MFT52xKy4
IkarusTrojan.Ransom.Spora
FortinetW32/Kryptik.CQXJ!tr
AVGWin32:Filecoder-AY [Trj]
Paloaltogeneric.ml

How to remove Zusy.326614?

Zusy.326614 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment