Malware

About “Zusy.352430 (B)” infection

Malware Removal

The Zusy.352430 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.352430 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • A process attempted to delay the analysis task by a long amount of time.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.352430 (B)?


File Info:

crc32: 7B36E894
md5: e2fa6a1238bcbe673cfc4191159f351c
name: E2FA6A1238BCBE673CFC4191159F351C.mlw
sha1: 13067b9c1960784a184a81b94d7b37bcd957ade7
sha256: 7721248f6c524da20b6f51b54e486e5d58766b29dfc5664a3e7a692dd2eb6655
sha512: f9132d4c7f65a5d2632db7d217d706aac91c113ce8b6a4110af145601793f50c7470213c337cca9f4c5b8577988fcce541501110698332fddce05e2b0806720d
ssdeep: 3072:tO+b0Q1QZQ6QuQP1pNOtcR1sGFHlx5QN0SGrgv+iwTfH9ZZSTPCEyS+Vja8ziry:txD1bOaR1Hbg0vr2+3fZSDCFZW8u2
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Tail noise Corporation. All rights reserved. Throw talk
InternalName: Final Thing
FileVersion: 1.1.0.806
CompanyName: Tail noise Corporation
ProductName: Tail noisexae Coverbreakxae
ProductVersion: 1.1.0.806
FileDescription: Tail noise Coverbreak
Round: Head had
OriginalFilename: Group.dll
Translation: 0x0409 0x04b0

Zusy.352430 (B) also known as:

Elasticmalicious (high confidence)
Qihoo-360Generic/Trojan.Dropper.1b1
McAfeeRDN/Isfb
MalwarebytesTrojan.Ursnif
SangforMalware
BitDefenderGen:Variant.Zusy.352430
K7AntiVirusTrojan ( 005742771 )
ArcabitTrojan.Zusy.D560AE
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HHYT
APEXMalicious
CynetMalicious (score: 90)
KasperskyHEUR:Trojan.Win32.Agent.gen
AlibabaTrojan:Win32/Kryptik.6a292995
MicroWorld-eScanGen:Variant.Zusy.352430
Ad-AwareGen:Variant.Zusy.352430
SophosGeneric PUA BD (PUA)
F-SecureTrojan.TR/AD.UrsnifDropper.hcfxt
DrWebTrojan.Gozi.770
TrendMicroTrojan.Win32.MALREP.THLOCBO
McAfee-GW-EditionRDN/Isfb
FireEyeGeneric.mg.e2fa6a1238bcbe67
EmsisoftGen:Variant.Zusy.352430 (B)
WebrootW32.Trojan.Gen
AviraTR/AD.UrsnifDropper.hcfxt
MAXmalware (ai score=87)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Zusy.352430
Acronissuspicious
ALYacSpyware.Ursnif
CylanceUnsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojan.Win32.MALREP.THLOCBO
RisingTrojan.Generic@ML.89 (RDML:O2gPtq6Y0sQ7cYatexAi0A)
IkarusTrojan.Win32.Crypt
FortinetW32/GenKryptik.EXTU!tr
AVGFileRepMalware

How to remove Zusy.352430 (B)?

Zusy.352430 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment