Malware

Should I remove “Zusy.304896”?

Malware Removal

The Zusy.304896 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.304896 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Attempts to modify UAC prompt behavior
  • Anomalous binary characteristics

Related domains:

raw.githubusercontent.com

How to determine Zusy.304896?


File Info:

crc32: 294A08F2
md5: c19b0374ec825dc37d70e02ff3098250
name: svchost.exe
sha1: a48d6367a9874a827ab585475a1306d43a8bfc47
sha256: d44a09c18ac230ae72b0a760476d2bef2d288ce67b7e6b7ebeabd0cbc837ba73
sha512: bf4c03cf4cdf79c6bcba2dc709b4b0b33547e0ee22542eff684086b806d13b4ca4fdcc991efb25c65f4ffd64a04e5b55dc2826c15915c10a5a265d7eb341b5f9
ssdeep: 24576:CF1BE94Ojx8EgjngK0M2WxVlLFElWNXIo/JhsMkNXquUO:SOpgzh7xVlLFEizJGRcun
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.304896 also known as:

MicroWorld-eScanGen:Variant.Zusy.304896
FireEyeGeneric.mg.c19b0374ec825dc3
McAfeeFareit-FTB!C19B0374EC82
ALYacGen:Variant.Zusy.304896
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00567bf01 )
BitDefenderGen:Variant.Zusy.304896
K7GWTrojan ( 00567bf01 )
Cybereasonmalicious.7a9874
BitDefenderThetaGen:NN.ZelphiF.34126.iHW@aSkOobli
SymantecInfostealer.Lokibot!43
ZonerTrojan.Win32.89754
AvastWin32:Trojan-gen
ClamAVWin.Dropper.LokiBot-7991551-0
GDataGen:Variant.Zusy.304896
KasperskyHEUR:Trojan.Win32.Kryptik.gen
NANO-AntivirusTrojan.Win32.TrjGen.hkvurh
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Zusy.304896 (B)
F-SecureTrojan.TR/AD.Inject.qjmfm
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Fareit.tc
SophosMal/Generic-S
IkarusTrojan.Inject
AviraTR/AD.Inject.qjmfm
MAXmalware (ai score=82)
ArcabitTrojan.Zusy.D4A700
ZoneAlarmHEUR:Trojan.Win32.Kryptik.gen
MicrosoftVirTool:Win32/CeeInject.JJ!bit
AhnLab-V3Suspicious/Win.Delphiless.X2066
VBA32TScope.Trojan.Delf
Ad-AwareGen:Variant.Zusy.304896
MalwarebytesTrojan.MalPack.DLF
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of Win32/Injector.EMHC
RisingTrojan.Injector!1.C72E (CLASSIC)
YandexTrojan.AvsArher.bTOmTw
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Injector.ELTZ!tr
AVGWin32:Trojan-gen
Qihoo-360HEUR/QVM05.1.C427.Malware.Gen

How to remove Zusy.304896?

Zusy.304896 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment