Malware

Zusy.377320 removal guide

Malware Removal

The Zusy.377320 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.377320 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Generates some ICMP traffic

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.qq.com
www.baidu.com
greenhomeland.com.cn
tj.peoss.com
file.greenhomeland.com.cn
pv.sohu.com

How to determine Zusy.377320?


File Info:

crc32: 8238DD83
md5: 41392139f782c65dbce9ffdd5e0e40a6
name: 41392139F782C65DBCE9FFDD5E0E40A6.mlw
sha1: 183e05907e17473893cfa59736991e322b507a10
sha256: 8ca60fd9f871dfefa65e04fe0fe9411a9f53065419ca639bf05b6bad385f9c0d
sha512: 86a33f318e91e5fd030be5e6f6a4ac57020ad138720c3b21369b14df4ead092601c15628d2c14a65caf63475d2377f13cfaefd15c5a0f3b545d0e7a4da53309f
ssdeep: 24576:jXU09t8XLX8hf6VAYCG6WouT8wadrWU0gA8:jEutzfsCG5h9aBX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) CopyLick. All rights reserved.
FileVersion: 2.0.3.1312
CompanyName: CopyLick? System
Comments: CopyLick Corporation
ProductName: CopyLick
ProductVersion: 2.03.1312
FileDescription: CopyLick
Translation: 0x0804 0x04b0

Zusy.377320 also known as:

K7AntiVirusTrojan ( 0057b1f91 )
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Badur
ALYacGen:Variant.Zusy.377320
CylanceUnsafe
ZillyaTrojan.Obfuscated.Win32.95080
SangforTrojan.Win32.Badur.ky
AlibabaTrojan:Win32/GenCBL.c9f0c077
K7GWTrojan ( 0057b1f91 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/GenCBL.AJQ
AvastWin32:Trojan-gen
BitDefenderGen:Variant.Zusy.377320
ViRobotTrojan.Win32.Z.Zusy.1074200
MicroWorld-eScanGen:Variant.Zusy.377320
TencentWin32.Trojan.Adware.Lxfi
Ad-AwareGen:Variant.Zusy.377320
SophosMal/Generic-S
F-SecureTrojan.TR/AutoIt.ofubc
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Zusy.377320
EmsisoftGen:Variant.Zusy.377320 (B)
WebrootW32.Trojan.Gen
AviraTR/AutoIt.ofubc
Antiy-AVLTrojan/Generic.ASMalwS.30F6B20
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Script/Phonzy.A!ml
ArcabitTrojan.Zusy.D5C1E8
AegisLabTrojan.Win32.Badur.4!c
GDataGen:Variant.Zusy.377320
AhnLab-V3Malware/Win.Generic.R416907
McAfeeArtemis!41392139F782
MAXmalware (ai score=80)
VBA32Trojan.Badur
MalwarebytesTrojan.Dropper
TrendMicro-HouseCallTROJ_GEN.R06CH0DFJ21
RisingAdware.Agent!1.D343 (CLASSIC)
IkarusTrojan.Win32.Generic
MaxSecureTrojan.Malware.74007784.susgen
FortinetW32/GenCBL.AJQ!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Trojan.Generic

How to remove Zusy.377320?

Zusy.377320 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment