Malware

What is “Zusy.361104”?

Malware Removal

The Zusy.361104 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.361104 virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.361104?


File Info:

crc32: AB098E49
md5: 605fb4e9bfcd39e07a3bedfe4397210e
name: 605FB4E9BFCD39E07A3BEDFE4397210E.mlw
sha1: 2c6e4666db8b3ed36067f2493be1320b58471488
sha256: 35156782da0013be8a18101cdba33d71a5d102b5fdeabe99c015f7c94d120179
sha512: 49f8cd1b04f9efe070a65e09f4f2e905c14445c7702fa9c899e853097e5b691a8a14ca7783bb532ca9a728261fdbc34a23fc4270f1a0785592931c6791c35acd
ssdeep: 1536:4kq6M6S6RxTWGpFIMusHBnzMZwnwFRBbwCKSE8HhBr:4lp6S6RAGfosHlzMZEmJzH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: ICWCONN2
FileVersion: 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.00.2900.2180
FileDescription: Internet Connection Wizard
OriginalFilename: ICWCONN2.EXE
Translation: 0x0409 0x04b0

Zusy.361104 also known as:

BkavW32.AIDetect.malware1
LionicVirus.Win32.Virut.lif1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealW32.Virut.G
ALYacGen:Variant.Zusy.361104
CylanceUnsafe
SangforTrojan.Win32.Wacatac.C
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaVirus:Win32/Vitro.dd681fe1
Cybereasonmalicious.9bfcd3
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Vitro [Inf]
ClamAVWin.Virus.Virut-5898123-1
BitDefenderGen:Variant.Zusy.361104
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
MicroWorld-eScanGen:Variant.Zusy.361104
TencentWin32.Trojan.Pe.Wlpn
Ad-AwareGen:Variant.Zusy.361104
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34266.gm1@amBR4cni
TrendMicroPE_VIRUX.GEN-4
McAfee-GW-EditionBehavesLike.Win32.Virut.cm
FireEyeGeneric.mg.605fb4e9bfcd39e0
EmsisoftGen:Variant.Zusy.361104 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Agent.dqki
AviraTR/Patched.Ren.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Zusy.D58290
GDataGen:Variant.Zusy.361104
McAfeeArtemis!605FB4E9BFCD
MAXmalware (ai score=82)
TrendMicro-HouseCallPE_VIRUX.GEN-4
RisingTrojan.Generic@ML.84 (RDML:cYvkj1F/WuECWV1hig5NiA)
IkarusVirus.Win32.Virut
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat.PALLAS.H
AVGWin32:Vitro [Inf]
Paloaltogeneric.ml

How to remove Zusy.361104?

Zusy.361104 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment