Malware

How to remove “Zusy.308911”?

Malware Removal

The Zusy.308911 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.308911 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

nonserc.be
optumbull.be
eksyghskgsbakrys.com
msrgejsdyvekadh.com

How to determine Zusy.308911?


File Info:

crc32: BEDD70CD
md5: ec568dd50680b6335ed20cde01cdeb45
name: EC568DD50680B6335ED20CDE01CDEB45.mlw
sha1: 7a89259bb8df2ef3ffd477be3d29e937f91374f4
sha256: 239f0d84843be92b9054b8d172de3c37d6fdb0acf62ba3ae616530b2bd98e551
sha512: bf58bdc8491ac73fd8353aa13380c097568651aca36849882d6478e430075df68fa9dd8529b1089209a798972e8c274fe7dcee9a98d8bde83fb27e46583f0fb6
ssdeep: 6144:/CGwmZlYGe89uvhBAx6a0b3gRmStiRbed:/BJRihY6a0bOm6Ged
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.308911 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005485311 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.547
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.308911
CylanceUnsafe
ZillyaTrojan.Krap.Win32.7899
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 005485311 )
Cybereasonmalicious.50680b
BaiduWin32.Virus.Krap.a
CyrenW32/Trojan.CCU.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.AJXZ
APEXMalicious
AvastWin32:MBRlock-CG [Trj]
ClamAVWin.Trojan.Zbot-36436
KasperskyVirus.Win32.Krap.it
BitDefenderGen:Variant.Zusy.308911
NANO-AntivirusTrojan.Win32.ArchSms.bsaqhn
MicroWorld-eScanGen:Variant.Zusy.308911
TencentWin32.Virus.Krap.Alsg
Ad-AwareGen:Variant.Zusy.308911
SophosML/PE-A + Troj/ArchSMS-AC
ComodoApplicUnwnt.Win32.Hoax.ArchSMS.RXU@4nkp87
BitDefenderThetaAI:Packer.234B52A118
VIPRETrojan.Win32.Kanots.a (v)
McAfee-GW-EditionBehavesLike.Win32.ZBot.ch
FireEyeGeneric.mg.ec568dd50680b633
EmsisoftGen:Variant.Zusy.308911 (B)
JiangminTrojanDropper.Dapato.fnb
AviraTR/PSW.Panda.lbjmt
eGambitUnsafe.AI_Score_83%
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
GDataGen:Variant.Zusy.308911
AhnLab-V3Trojan/Win32.Zbot.R22644
Acronissuspicious
McAfeePWS-Zbot.gen.ro
MAXmalware (ai score=100)
VBA32Malware-Cryptor.Limpopo
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/Pacrypt.D
RisingTrojan.Generic@ML.96 (RDML:voATTn4FonMyN0IMpueiNg)
YandexTrojan.GenAsa!8pqCZCUDUNs
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.RO!tr
AVGWin32:MBRlock-CG [Trj]
Paloaltogeneric.ml

How to remove Zusy.308911?

Zusy.308911 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment