Malware

Zusy.301068 malicious file

Malware Removal

The Zusy.301068 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.301068 virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Installs itself for autorun at Windows startup
  • Attempts to create or modify system certificates

Related domains:

z.whorecord.xyz
a.tomx.xyz
downapp.baidu.com
www.ipip.net
en.ipip.net
265g.site

How to determine Zusy.301068?


File Info:

crc32: A5EE73B8
md5: 0fef12163cc0b35ddf2faabb0524951a
name: c.exe
sha1: 2296a7b184e5afbd9c1db0833898a101639cfc8a
sha256: bb8e9fea2563d6a622eb66b286281de7f3075482e43e1dd8045085366bb4ec2d
sha512: cc03dc854d4b57e2d21bd0eec2c07156fc1c1fe70eec3c873faccb0a81fc9b46b57ab22c7d8363474b697e76c5769c7b56c962a347c770b3ee627741c992864e
ssdeep: 1536:8jCU1I2vBgP3kt5aFnz6Mlepb5h0HIO6jt7XOMa9sxWgeLF3td:Mb1I2vOq0Fnzvlepb5bOwXANgIFd
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Zusy.301068 also known as:

MicroWorld-eScanGen:Variant.Zusy.301068
FireEyeGeneric.mg.0fef12163cc0b35d
Qihoo-360HEUR/QVM11.1.5B68.Malware.Gen
McAfeeArtemis!0FEF12163CC0
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Zusy.4!c
SangforMalware
K7AntiVirusAdware ( 005070c51 )
BitDefenderGen:Variant.Zusy.301068
K7GWAdware ( 005070c51 )
Cybereasonmalicious.63cc0b
TrendMicroTROJ_GEN.R002C0PEK20
BitDefenderThetaGen:NN.ZexaF.34110.emGfaOekk5l
CyrenW32/Trojan.XONM-1334
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
GDataWin32.Trojan.Agent.WP
KasperskyTrojan.Win32.Blamon.pun
NANO-AntivirusTrojan.Win32.Dwn.fpuyuw
TencentWin32.Trojan.Blamon.Lad
Endgamemalicious (moderate confidence)
SophosMal/Generic-S
F-SecureTrojan.TR/Downloader.Gen
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.kc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zusy.301068 (B)
IkarusTrojan.Win32.CoinMiner
F-ProtW32/Heuristic-245!Eldorado
JiangminTrojan/StartPage.pea
AviraTR/Downloader.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Dropper]/Win32.Dinwod.acqn
MicrosoftTrojan:Win32/Occamy.AA
ArcabitTrojan.Zusy.D4980C
ZoneAlarmTrojan.Win32.Blamon.pun
AhnLab-V3Malware/Win32.Generic.C2686175
Acronissuspicious
ALYacGen:Variant.Zusy.301068
VBA32BScope.Trojan.Downloader
ESET-NOD32a variant of Win32/Packed.BlackMoon.A potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R002C0PEK20
RisingTrojan.Tiggre!8.ED98 (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Generic.AP.194A60!tr
Ad-AwareGen:Variant.Zusy.301068
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Zusy.301068?

Zusy.301068 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment