Malware

Should I remove “Zusy.359111”?

Malware Removal

The Zusy.359111 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.359111 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

redirector.gvt1.com
r1—sn-4g5e6ne6.gvt1.com
update.googleapis.com

How to determine Zusy.359111?


File Info:

crc32: 36C2F2D3
md5: aea15cd65c274b282878d29460210d9c
name: AEA15CD65C274B282878D29460210D9C.mlw
sha1: c1e84bb88408c485fa0635fe1d74ec99cef36d82
sha256: 08639e98cf6c1379bb93b438681073d604ccbe57401153404885b4a090becb25
sha512: c3a37edf5f5e29357b570a4183f7ce8ce8ab5b3220359ad68e97f16a3c84f43fa3201be3f5fa19cb40946d623dec20e19e0d7f47bf22fc0593ce76e2a0881896
ssdeep: 6144:nvhsC1Qc3GTImC3eFPE9AGfJHeDcISxSP+ik8tFzFoeIa1y2NbrQPF2Ad:D1Qc3GT5PoJcXPAizPIKyiwNf
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.359111 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.359111
CAT-QuickHealBackdoor.Remcos
ALYacGen:Variant.Zusy.359111
CylanceUnsafe
VIPREVirTool.Win32.Obfuscator.da!k (v)
AegisLabTrojan.Win32.Remcos.m!c
SangforMalware
K7AntiVirusTrojan ( 0057574b1 )
BitDefenderGen:Variant.Zusy.359111
K7GWTrojan ( 0057574b1 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Kryptik.CTB.gen!Eldorado
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Backdoor.Win32.Remcos.gen
AlibabaBackdoor:Win32/Tnega.aa1c72a1
NANO-AntivirusVirus.Win32.Gen.ccmw
ViRobotTrojan.Win32.Z.Zusy.342528.JZ
Ad-AwareGen:Variant.Zusy.359111
EmsisoftGen:Variant.Zusy.359111 (B)
ComodoMalware@#3dcfzqrzxt6hx
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.DownLoader36.31733
TrendMicroTROJ_GEN.R06CC0GA121
McAfee-GW-EditionGenericRXNG-YT!AEA15CD65C27
FireEyeGeneric.mg.aea15cd65c274b28
SophosMal/Generic-S
IkarusTrojan.Inject
GDataGen:Variant.Zusy.359111
JiangminBackdoor.Remcos.clb
WebrootW32.Trojan.Gen
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan[Backdoor]/Win32.Remcos
KingsoftWin32.Hack.Undef.(kcloud)
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Zusy.D57AC7
ZoneAlarmHEUR:Backdoor.Win32.Remcos.gen
MicrosoftTrojan:Win32/Tnega.VAM!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R362258
McAfeeGenericRXNG-YT!AEA15CD65C27
MAXmalware (ai score=84)
VBA32Backdoor.Remcos
MalwarebytesSpyware.TelegramBot.TOR.Generic
PandaTrj/CI.A
ZonerTrojan.Win32.100200
ESET-NOD32a variant of Win32/Kryptik.HINZ
TrendMicro-HouseCallTROJ_GEN.R06CC0GA121
RisingTrojan.Kryptik!1.D103 (CLASSIC)
YandexTrojan.GenKryptik!OsK3f0b3hXk
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HIOZ!tr
BitDefenderThetaGen:NN.ZexaCO.34760.uuZ@a0oGfGoi
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.65c274
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.a07

How to remove Zusy.359111?

Zusy.359111 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment