Malware

How to remove “Zusy.350543”?

Malware Removal

The Zusy.350543 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.350543 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.350543?


File Info:

crc32: A5E54B5F
md5: e806d1194873fcfa4e31726710b75405
name: E806D1194873FCFA4E31726710B75405.mlw
sha1: 7d10bf42d901224bce67249b590c0dfc4f350653
sha256: ed37bb51af01647fde0a5b04a401fd278eba50cf2d5d0678f86227d27aecbc62
sha512: a12a90de586125da8e28c475b9fe658abce91f7130d93874b845f07a1fbc8662e77debedd9b548f9ac6d8c8831a79ff07dfdecb8448a4c0d5fcf4c97f603fa4f
ssdeep: 3072:655tEdAOKlggqO3G0jPonfYnoFMIkcXo0fSUa:/W26QfweMILXoXU
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

ProductVer: 2.0.9.29
FileV: 1.0.2.37
Translations: 0x0255 0x029d

Zusy.350543 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.350543
FireEyeGeneric.mg.e806d1194873fcfa
ALYacTrojan.Ransom.LockBit
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Midie.4!c
SangforMalware
K7AntiVirusTrojan ( 00573aca1 )
BitDefenderGen:Variant.Zusy.350543
K7GWTrojan ( 00573aca1 )
Cybereasonmalicious.2d9012
BitDefenderThetaGen:NN.ZexaF.34658.jmGfae5GjFkO
CyrenW32/Trojan.RNMK-8029
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HHRW
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Glupteba-9800473-0
KasperskyTrojan.Win32.DelShad.flu
AlibabaTrojan:Win32/DelShad.3285e5b8
ViRobotTrojan.Win32.Z.Kryptik.154624.PN
TencentWin32.Trojan.Raas.Auto
Ad-AwareGen:Variant.Zusy.350543
EmsisoftTrojan.Crypt (A)
ComodoMalware@#10o38yh5b2m49
F-SecureTrojan.TR/Crypt.Agent.rudod
DrWebTrojan.Encoder.33249
TrendMicroTROJ_GEN.R002C0DKR20
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SophosMal/Generic-S
AviraTR/Crypt.Agent.rudod
KingsoftWin32.Troj.Generic.a.(kcloud)
MicrosoftTrojan:Win32/Ranumbot.RQ!MSR
ArcabitTrojan.Zusy.D5594F
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
ZoneAlarmTrojan.Win32.DelShad.flu
GDataGen:Variant.Zusy.350543
CynetMalicious (score: 100)
Acronissuspicious
McAfeeArtemis!E806D1194873
MAXmalware (ai score=100)
VBA32BScope.Trojan.DelShad
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0DKR20
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HHTS!tr
AVGWin32:BotX-gen [Trj]
AvastWin32:BotX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM11.1.8BAA.Malware.Gen

How to remove Zusy.350543?

Zusy.350543 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment