Malware

Zusy.371378 removal

Malware Removal

The Zusy.371378 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.371378 virus can do?

  • Unconventionial language used in binary resources: Korean
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.371378?


File Info:

crc32: DB1BE927
md5: bcb427c93c3e61edd08c19a3b07ffcaf
name: BCB427C93C3E61EDD08C19A3B07FFCAF.mlw
sha1: 5d47aec8a3f2a0fc27230105bdf9870ab325e023
sha256: 218f22d4b401696a4076b588e8a528bbac76cd53fe61af5b740edbaebfad91e6
sha512: 2214390b6ef74c96773d765c95e579c892cf05d216c5f8e06570d60f54be478e465a1b1b74a85ccf07d4fc4dde49dd746ab1cb51bcd4507bf7540411ed783627
ssdeep: 384:8qCfbOf8BZHXICfZS9DTEHnRQNSun/WGaWBWXcWgIH1:a+MZHl7WRCiIV
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: qappsrv
FileVersion: 5.1.2600.0 (xpclient.010817-1148)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 5.1.2600.0
FileDescription: Query Terminal Server Utility
OriginalFilename: qappsrv.exe
Translation: 0x0409 0x04b0

Zusy.371378 also known as:

LionicTrojan.Win32.Zusy.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.371378
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaVirus:Win32/Virut.8b9b9399
Cybereasonmalicious.93c3e6
CyrenW32/Virut.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Virtu-F [Inf]
BitDefenderGen:Variant.Zusy.371378
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
MicroWorld-eScanGen:Variant.Zusy.371378
TencentWin32.Trojan.Patched.Pjdk
Ad-AwareGen:Variant.Zusy.371378
SophosML/PE-A
ComodoMalware@#cd792d26mycw
BitDefenderThetaGen:NN.ZexaF.34294.dq1@aKclxVgO
McAfee-GW-EditionBehavesLike.Win32.Virut.pz
FireEyeGeneric.mg.bcb427c93c3e61ed
EmsisoftGen:Variant.Zusy.371378 (B)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Zpevdo.A
GDataGen:Variant.Zusy.371378
Acronissuspicious
MAXmalware (ai score=88)
TrendMicro-HouseCallTROJ_GEN.R002H0CIO21
IkarusVirus.Win32.Virut
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.F
AVGWin32:Virtu-F [Inf]
Paloaltogeneric.ml

How to remove Zusy.371378?

Zusy.371378 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment