Malware

Zusy.310879 removal instruction

Malware Removal

The Zusy.310879 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.310879 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Zusy.310879?


File Info:

crc32: AB6B0B23
md5: f92437f9c01c5d6011b949e868f58510
name: twwtno.exe
sha1: 68234ade80cff538d47b7dc3f3fda7369f70530b
sha256: 50d992723747ed6004f10433bb874cddfb21f086c7d308fde1484c1edc078edd
sha512: 478e6c81dfaa1edbc38afb215914014bca4c1d3949c08745d696df689ba45f62ba143c3076d585157cd8772709be67ed5ea139be34c5dbf5e67546846b90dfbe
ssdeep: 6144:zDp1jvG51BTTBu7trVL2S+Kz15tZgeefn3BU2d8mE5h9OgqI:zPjvW1BTTw7trRZzHDg9fny2dv0l5
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2019
InternalName: HelpFun
FileVersion: 2.1.0.5
CompanyName: Company
ProductName: x8f85x52a9x68c0x6d4bx6a21x5757
ProductVersion: 2.1.0.5
FileDescription: x5e94x7528x7a0bx5e8fx6269x5c55x6a21x5757
OriginalFilename: HelpFun.exe
Translation: 0x0804 0x04b0

Zusy.310879 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.310879
FireEyeGeneric.mg.f92437f9c01c5d60
McAfeeGenericRXAA-AA!F92437F9C01C
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1363122
K7AntiVirusTrojan ( 0056a8131 )
BitDefenderGen:Variant.Zusy.310879
K7GWTrojan ( 0056a8131 )
CrowdStrikewin/malicious_confidence_60% (W)
CyrenW32/S-4eb9485d!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Gofot.vho
AlibabaTrojan:Win32/CryptInject.2e3a059c
NANO-AntivirusTrojan.Win32.Gofot.hqhmyy
ViRobotTrojan.Win32.Z.Agent.278566.KW
RisingTrojan.Agent!8.B1E (CLOUD)
Ad-AwareGen:Variant.Zusy.310879
EmsisoftGen:Variant.Zusy.310879 (B)
Comodo.UnclassifiedMalware@0
F-SecureTrojan.TR/Agent.gzuop
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R01FC0RH820
SophosTroj/Agent-BELS
IkarusTrojan.Win32.Agent
JiangminTrojan.Gofot.ava
AviraTR/Agent.gzuop
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.Gofot
MicrosoftTrojan:Win32/CryptInject.SBR!MSR
ArcabitTrojan.Zusy.D4BE5F
ZoneAlarmHEUR:Trojan.Win32.Gofot.vho
GDataGen:Variant.Zusy.310879
AhnLab-V3Trojan/Win32.Agent.C4175341
BitDefenderThetaGen:NN.ZexaF.34186.ru1@aezP0Efj
ALYacGen:Variant.Zusy.310879
VBA32BScope.Trojan.Wacatac
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/Agent.ACCK
TrendMicro-HouseCallTROJ_GEN.R01FC0RH820
TencentMalware.Win32.Gencirc.10cde546
FortinetW32/Agent.ACCK!tr
AVGWin32:Trojan-gen
Qihoo-360Generic/HEUR/QVM10.2.FC5B.Malware.Gen

How to remove Zusy.310879?

Zusy.310879 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment