Malware

Zusy.305209 removal instruction

Malware Removal

The Zusy.305209 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.305209 virus can do?

  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Performs some HTTP requests

Related domains:

api.xp666.com
download.xp666.com

How to determine Zusy.305209?


File Info:

crc32: 68F2D1F5
md5: 59688be91295571d554964c9a679f6de
name: idocdownwx_32761.exe
sha1: c54a260d477328c0118cd9541adf20606e1e689e
sha256: 04ef9cbe3a8b1d6b96eead73e0744387b42e0ba252f970f51061ebb00268cfd5
sha512: eeecf04b7dca04d1ed134c922f5b859fc6764f82dab576814460f812b07f755f7f8649560536fca1b8e11ea982bf30750aa287d1e25d7f0c2d9641a7a6312898
ssdeep: 49152:J9XANAO/HI5jAS2jDQ0dYAfh//UbT1HMsLLTlbINuqfdB:JtASO/ocn8Afh//U5Ohfd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.305209 also known as:

MicroWorld-eScanGen:Variant.Zusy.305209
FireEyeGen:Variant.Zusy.305209
CAT-QuickHealTrojanDownloader.Agent
McAfeeArtemis!59688BE91295
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Agent.a!c
SangforMalware
K7AntiVirusTrojan ( 0055e4261 )
BitDefenderGen:Variant.Zusy.305209
K7GWTrojan ( 0055e4261 )
Cybereasonmalicious.912955
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
GDataGen:Variant.Zusy.305209
KasperskyHEUR:Trojan-Downloader.Win32.Agent.gen
RisingDownloader.Agent!8.B23 (CLOUD)
EmsisoftGen:Variant.Zusy.305209 (B)
F-SecureTrojan.TR/Redcap.ypbjv
ZillyaTrojan.Duote.Win32.153
TrendMicroTROJ_GEN.R002C0WF520
McAfee-GW-EditionBehavesLike.Win32.Dropper.wh
SophosTroj/AutoG-HY
IkarusTrojan.Win32.Duote
CyrenW32/Trojan.WXIU-0974
JiangminTrojanDownloader.Agent.fwoe
MaxSecureTrojan.Malware.1207211.susgen
AviraTR/Redcap.ypbjv
MAXmalware (ai score=80)
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Zusy.D4A839
ZoneAlarmHEUR:Trojan-Downloader.Win32.Agent.gen
MicrosoftTrojan:Win32/Vigorf.A
CynetMalicious (score: 85)
AhnLab-V3Malware/Gen.Generic.C2822749
VBA32TScope.Trojan.Delf
ALYacGen:Variant.Zusy.305209
Ad-AwareGen:Variant.Zusy.305209
MalwarebytesTrojan.Downloader.Aspack
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Duote.A
TrendMicro-HouseCallTROJ_GEN.R002C0WF520
YandexTrojan.Duote!
FortinetW32/Duote.A!tr
BitDefenderThetaAI:Packer.73B8284619
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_70% (D)
Qihoo-360Generic/HEUR/QVM05.1.BD4C.Malware.Gen

How to remove Zusy.305209?

Zusy.305209 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment