Malware

Zusy.342038 (file analysis)

Malware Removal

The Zusy.342038 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.342038 virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a slightly modified copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
latua.nsupdate.info

How to determine Zusy.342038?


File Info:

crc32: FC4FB436
md5: 655cb4bcce95ee3a5b2fd6962cabe4e1
name: 655CB4BCCE95EE3A5B2FD6962CABE4E1.mlw
sha1: cbe030e0d3bd837b78bec5046ef3dc27f08473cd
sha256: 9fe18338a0e8754bbedb4b3d72d47b7d9e7c3ed7bbbd76f39e4db9c13f0d1d5b
sha512: d10a23ead4f5efffe69a5dc49efd4bb3f5842ca0766c946ed2c14522d52bd8ccce8abcc673fe2cca225a961236d68e290b959d997cfeb6c3757def4e925c0ec5
ssdeep: 12288:QuUc1FBZNmdQo+Yn6Pjvu+e5Z1qbrqvQzbDdNNwokR:QuXjBZLS6P7UZ1qivsNEJR
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.342038 also known as:

DrWebTrojan.DownLoader35.26188
MicroWorld-eScanGen:Variant.Zusy.342038
CAT-QuickHealTrojan.Multi
McAfeeGenericRXMP-WD!655CB4BCCE95
CylanceUnsafe
K7AntiVirusTrojan ( 00572ab11 )
K7GWTrojan ( 00572ab11 )
TrendMicroTROJ_GEN.R06EC0PKI20
BitDefenderThetaGen:NN.ZexaF.34634.JuZ@aCcktZmi
CyrenW32/Kryptik.CJZ.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:RATX-gen [Trj]
ClamAVWin.Packed.Midie-9794561-0
KasperskyHEUR:Trojan-Spy.Win32.Noon.pef
BitDefenderGen:Variant.Zusy.342038
TencentMalware.Win32.Gencirc.11b1309b
Ad-AwareGen:Variant.Zusy.342038
EmsisoftGen:Variant.Zusy.342038 (B)
F-SecureTrojan.TR/Crypt.Agent.qmxvu
VIPREVirTool.Win32.Obfuscator.da!k (v)
InvinceaMal/Generic-S
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
SophosMal/Generic-S
IkarusWin32.Outbreak
GDataGen:Variant.Zusy.342038
AviraTR/Crypt.Agent.qmxvu
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Zusy.D53816
ZoneAlarmHEUR:Trojan-Spy.Win32.Noon.pef
MicrosoftTrojan:Win32/Wacatac.C!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Crypt.R355384
Acronissuspicious
VBA32BScope.Trojan.Wacatac
MAXmalware (ai score=88)
MalwarebytesBackdoor.Remcos
ESET-NOD32a variant of Win32/Kryptik.HHJA
TrendMicro-HouseCallTROJ_GEN.R06EC0PKI20
RisingTrojan.Kryptik!1.CEB6 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HHJA!tr
AVGWin32:RATX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Zusy.342038?

Zusy.342038 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment