Malware

How to remove “Zusy.338505”?

Malware Removal

The Zusy.338505 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.338505 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Creates RWX memory
  • Starts servers listening on 127.0.0.1:0
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Executed a process and injected code into it, probably while unpacking
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
whatismyipaddress.com

How to determine Zusy.338505?


File Info:

crc32: FA05D75E
md5: a65c60e28553d2f1b3109cf00a7130d3
name: A65C60E28553D2F1B3109CF00A7130D3.mlw
sha1: 34794cf2cadaad7d4681b9940cc880389bc33e37
sha256: 5b5c40a87df0ef2e2bf553025033885176bb0e016fb1f9661d8131be6b46764a
sha512: 6b05f3e0ab05a8887a37a5e4baaf93c4769c28ed4a9f14de055959308dc25bdcd9dcb6edf0ba6440b489fc04bd3640239c6fc695eba748c33f73d92b2061e2bd
ssdeep: 24576:LC9yfpQXG5qu/W2oo7KX4DO7CElxZ2Ww9XdxYl3:ZnqmxfKIeNlcRdxy
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Co9gfd324p.
InternalName:
FileVersion: 592341t6
CompanyName: v43fvguyitr
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 817647453256
FileDescription:
OriginalFilename:
Translation: 0x0409 0x04e4

Zusy.338505 also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Zusy.338505
FireEyeGeneric.mg.a65c60e28553d2f1
McAfeeFareit-FZN!A65C60E28553
SangforMalware
K7AntiVirusTrojan ( 00572b511 )
BitDefenderGen:Variant.Zusy.338505
K7GWTrojan ( 00572b511 )
CrowdStrikewin/malicious_confidence_80% (D)
InvinceaGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZelphiF.34634.hH0@aSQJw7mi
SymantecInfostealer.Lokibot!43
APEXMalicious
AvastWin32:CoinminerX-gen [Trj]
Ad-AwareGen:Variant.Zusy.338505
DrWebTrojan.PWS.Stealer.26517
McAfee-GW-EditionBehavesLike.Win32.Fareit.th
EmsisoftTrojan.Injector (A)
SentinelOneStatic AI – Malicious PE
MicrosoftPWS:Win32/Fareit!ml
ArcabitTrojan.Zusy.D52A49
GDataGen:Variant.Zusy.338505
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Fareit.R354591
VBA32TScope.Trojan.Delf
MalwarebytesTrojan.MalPack.DLF
ESET-NOD32MSIL/Autorun.Spy.Agent.AU
RisingTrojan.Injector!1.CEB9 (CLASSIC)
MAXmalware (ai score=82)
eGambitUnsafe.AI_Score_100%
FortinetW32/Injector.ENTV!tr
AVGWin32:CoinminerX-gen [Trj]
Cybereasonmalicious.28553d
Qihoo-360HEUR/QVM20.1.3A86.Malware.Gen

How to remove Zusy.338505?

Zusy.338505 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment