Malware

About “Zusy.305315” infection

Malware Removal

The Zusy.305315 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.305315 virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.305315?


File Info:

crc32: C867D1DC
md5: 8ee0d9d1a16941fd24baa70731fecd0e
name: web2.exe
sha1: 55419a32c2a2d1feee73070e804fcc2f4b232e71
sha256: 6de1ce049ca1c37daf392751ee6d32e4f2dbc31cdfb18ac1c6449b0b89cc8f58
sha512: 71e7bde29de3b8b97efd8d4fd9a2fa301c7799e9e3321897e91357dcbf07d3f4b7ffd3e8d2949513622701ce1de200a2d6e7f4306f7c2531845fce3f1c99f587
ssdeep: 1536:ulbCGz1zTo10PqqZlaS26PIW+kHe17u8zgsUop+GGa4PeVIIP:ngM09PAh7bUsVcGG4VIIP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2019 Google LLC. All rights reserved.
InternalName: chrome_proxy
CompanyShortName: Google
FileVersion: 83.0.4103.61
CompanyName: Google LLC
ProductShortName: Chrome
ProductName: Google Chrome
LastChange: 94f915a8d7c408b09cc7352161ad592299f384d2-refs/branch-heads/4103@#561
ProductVersion: 83.0.4103.61
FileDescription: Google Chrome
OriginalFilename: chrome_proxy.exe
Official Build: 1
Translation: 0x0409 0x04b0

Zusy.305315 also known as:

MicroWorld-eScanGen:Variant.Zusy.305315
FireEyeGeneric.mg.8ee0d9d1a16941fd
McAfeeGenericRXKU-MV!8EE0D9D1A169
CylanceUnsafe
ZillyaTrojan.GenKryptik.Win32.49052
SangforMalware
K7AntiVirusTrojan ( 005679eb1 )
BitDefenderGen:Variant.Zusy.305315
K7GWTrojan ( 005679eb1 )
Cybereasonmalicious.1a1694
APEXMalicious
AvastWin32:Trojan-gen
GDataGen:Variant.Zusy.305315
RisingBackdoor.Zegost!8.177 (TFE:dGZlOgXsm/wednIV/g)
Ad-AwareGen:Variant.Zusy.305315
DrWebTrojan.DownLoader33.47696
Invinceaheuristic
McAfee-GW-EditionGenericRXKU-MV!8EE0D9D1A169
EmsisoftGen:Variant.Ulise.108644 (B)
JiangminBackdoor.Lotok.hx
Antiy-AVLTrojan[Backdoor]/Win32.Lotok
Endgamemalicious (high confidence)
ArcabitTrojan.Zusy.D4A8A3
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Zegost.BW
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34126.gq0@amo0ahdj
MAXmalware (ai score=89)
VBA32BScope.Trojan.Dynamer
MalwarebytesBackdoor.Farfli
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/GenKryptik.EHYK
TencentMalware.Win32.Gencirc.10cdd188
SentinelOneDFI – Suspicious PE
FortinetW32/GenKryptik.EHYK!tr
AVGWin32:Trojan-gen

How to remove Zusy.305315?

Zusy.305315 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment