Malware

Should I remove “Zusy.330115”?

Malware Removal

The Zusy.330115 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.330115 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

serapide.zapto.org

How to determine Zusy.330115?


File Info:

crc32: F75EEF87
md5: 28b170e489943fee76e12032c3dcce5b
name: 28B170E489943FEE76E12032C3DCCE5B.mlw
sha1: 9d0eafbf0dab5129eddefd4f45ba2538cde84657
sha256: 2b2cec03f74b35b0815f3ff774bdd7f3b1d3ae4a4683521186bb53ed7cd41afc
sha512: 188c39730de44861014b983f77da5649c5ff7ad155cab0438cad7fc1729c024a837f42d207e018a519c15c97eb227ca6cfc75bf9771382d77882c0429b4b5ffe
ssdeep: 49152:di2QW7l5eu6wdh65p3x7Kd7mVFqq9pnuCZnePB:dlQS5eu6ldKdKVdznuuaB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.330115 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004bfb711 )
Elasticmalicious (high confidence)
DrWebTrojan.Inject1.3420
CynetMalicious (score: 100)
CAT-QuickHealRansom.Blocker.19974
ALYacGen:Variant.Zusy.330115
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.53162
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Starter.ali1001008
K7GWTrojan ( 004bfb711 )
Cybereasonmalicious.489943
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.SNV
APEXMalicious
AvastWin32:MBRlock-DV [Trj]
KasperskyTrojan-Ransom.Win32.Blocker.fqcw
BitDefenderGen:Variant.Zusy.330115
NANO-AntivirusTrojan.Win32.Dapato.bbueig
MicroWorld-eScanGen:Variant.Zusy.330115
TencentTrojan.Win32.Blocker.yi
Ad-AwareGen:Variant.Zusy.330115
SophosMal/Generic-R + Troj/Agent-BDRA
ComodoTrojWare.Win32.Bitrep.SNV@86bc71
BitDefenderThetaAI:Packer.68042D5919
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Worm.tc
FireEyeGeneric.mg.28b170e489943fee
EmsisoftGen:Variant.Zusy.330115 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.cqd
WebrootW32.Trojan.Gen
eGambitUnsafe.AI_Score_95%
Antiy-AVLTrojan/Generic.ASBOL.C5F7
MicrosoftAdware:Win32/Adposhel
ZoneAlarmTrojan-Ransom.Win32.Blocker.fqcw
GDataGen:Variant.Zusy.330115
AhnLab-V3Dropper/Win32.Dapato.R67309
Acronissuspicious
McAfeeGenericR-HGH!28B170E48994
MAXmalware (ai score=87)
VBA32TrojanDropper.Dapato
PandaTrj/Genetic.gen
RisingTrojan.Injector!1.BB2B (CLASSIC)
YandexTrojan.GenAsa!CxJTXWmEIV4
IkarusTrojan.Win32.Agent
FortinetW32/Dropper.XUQ!tr
AVGWin32:MBRlock-DV [Trj]
Paloaltogeneric.ml

How to remove Zusy.330115?

Zusy.330115 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment