Malware

Should I remove “Zusy.311488”?

Malware Removal

The Zusy.311488 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.311488 virus can do?

  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.xp666.com
download.xp666.com

How to determine Zusy.311488?


File Info:

crc32: F66915FC
md5: 71c734e5235fcc9bd2df25e678d4008f
name: comtool_41935.exe
sha1: c66610cf1bf42ec9730867ec4b09c6e7c82f75a2
sha256: 9b0141917b4763fd1854ee21d939df41f6a4c4bf55b9fea63347e6f6fa37cb3e
sha512: 7558db12c3019904f84c9eabe3012f04a26292312e5a7468c4456f72ca597aedaa969fa39069fd5748e98d40af7a604d5ae59d6ccb9aa209937d90f45fae56f9
ssdeep: 49152:niR51+hGshBGSE0rBdEc+7tiV74AbjHs/TiDTO/wTBlhvkgdz:niR6hSaD+7tiV74//N/6Blnd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyrightxff08Cxff092018
FileVersion: 1.22.4.250
ProductVersion: 1.2
Translation: 0x0804 0x03a8

Zusy.311488 also known as:

MicroWorld-eScanGen:Variant.Zusy.311488
FireEyeGen:Variant.Zusy.311488
McAfeeGenericRXAA-AA!71C734E5235F
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0055e4261 )
BitDefenderGen:Variant.Zusy.311488
K7GWTrojan ( 0055e4261 )
Invinceaheuristic
BitDefenderThetaGen:NN.ZelphiF.34196.UV0@au2Orcoi
CyrenW32/Trojan.DKGH-8876
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyHEUR:Trojan-Downloader.Win32.Agent.gen
NANO-AntivirusTrojan.Win32.Redcap.hrwrgd
AegisLabTrojan.Win32.Agent.a!c
TencentMalware.Win32.Gencirc.11acdb72
Ad-AwareGen:Variant.Zusy.311488
F-SecureTrojan.TR/Redcap.qvlch
TrendMicroTROJ_GEN.R002C0WHE20
SophosMal/Generic-S
SentinelOneDFI – Suspicious PE
JiangminTrojanDownloader.Agent.fwoe
WebrootW32.Gen.BT
AviraTR/Redcap.qvlch
Antiy-AVLTrojan/Win32.Duote
MicrosoftTrojan:Win32/Ymacco.AA9B
ArcabitTrojan.Zusy.D4C0C0
ZoneAlarmHEUR:Trojan-Downloader.Win32.Agent.gen
GDataGen:Variant.Zusy.311488
AhnLab-V3Trojan/Win32.Agent.C4182275
VBA32TScope.Trojan.Delf
ALYacGen:Variant.Zusy.311488
MAXmalware (ai score=100)
MalwarebytesTrojan.Downloader
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Duote.A
TrendMicro-HouseCallTROJ_GEN.R002C0WHE20
RisingDownloader.Agent!8.B23 (CLOUD)
IkarusTrojan.Win32.Duote
FortinetW32/Duote.A!tr
AVGWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Generic/HEUR/QVM05.1.3BC9.Malware.Gen

How to remove Zusy.311488?

Zusy.311488 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment