Malware

Zusy.304210 information

Malware Removal

The Zusy.304210 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.304210 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config

Related domains:

z.whorecord.xyz
xz.qd588.cn
a.tomx.xyz

How to determine Zusy.304210?


File Info:

crc32: F1A2B767
md5: 3f2fbb775d5b11b54fc63adb6129a70a
name: setdate.exe
sha1: 09f492430307624f4f39f14eaa328c9c82bcfbcf
sha256: 840db87dbda8200529168cd3db4cb2dc46a8f5d3c7b3ef489c0f0f9d2a7a696e
sha512: d2fc153df899ad0c96ec72ad401f18a52681af98c1288e796c645b3724c5948a768509cec585321cf07c4a2e4c83a34d60a70406e840c76aff4889944d9b976b
ssdeep: 6144:Nhg9YkrZnrkVi66kWu5phdnpvDA/rOS4rly9EQVeCkVxAHderOpse:NhVVi661u5phdn6/iSglyveKHder
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2019 x6269x5c55x8f85x52a9
ProductVersion: 1.3.7.7
ProductName: x529fx80fdx6a21x5757
FileVersion: 1.3.7.7
FileDescription: x5e94x7528x7a0bx5e8fx6269x5c55
Translation: 0x0804 0x04b0

Zusy.304210 also known as:

MicroWorld-eScanGen:Variant.Zusy.304210
FireEyeGen:Variant.Zusy.304210
CAT-QuickHealBackdoor.Agent
McAfeeGenericRXKG-ZS!3F2FBB775D5B
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0055d4161 )
BitDefenderGen:Variant.Zusy.304210
K7GWTrojan ( 0055d4161 )
CyrenW32/Trojan.SDYP-0369
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.ABIK
TrendMicro-HouseCallTROJ_GEN.R002C0PEQ20
AvastWin32:Trojan-gen
KasperskyBackdoor.Win32.Agent.mytvxs
AlibabaBackdoor:Win32/qouco.0f290e33
NANO-AntivirusTrojan.Win32.StartPage1.hkvsfj
AegisLabTrojan.Win32.Agent.m!c
APEXMalicious
TencentMalware.Win32.Gencirc.118028d6
Endgamemalicious (high confidence)
SophosMal/Generic-S
ComodoMalware@#3normxhha47s1
F-SecureTrojan.TR/Agent.qouco
DrWebTrojan.StartPage1.58545
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PEQ20
McAfee-GW-EditionGenericRXKG-ZS!3F2FBB775D5B
EmsisoftGen:Variant.Zusy.304210 (B)
GDataGen:Variant.Zusy.304210
AviraTR/Agent.qouco
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftTrojan:Win32/Occamy.AA
ArcabitTrojan.Zusy.D4A452
ZoneAlarmBackdoor.Win32.Agent.mytvxs
VBA32BScope.Adware.Presenoker
ALYacGen:Variant.Zusy.304210
Ad-AwareGen:Variant.Zusy.304210
PandaTrj/GdSda.A
RisingTrojan.StartPage!1.C1A0 (CLOUD)
IkarusTrojan.Win32.Agent
FortinetW32/Agent.ABIK!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.449

How to remove Zusy.304210?

Zusy.304210 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment