Malware

What is “Zusy.289154”?

Malware Removal

The Zusy.289154 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.289154 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Zusy.289154?


File Info:

crc32: 810571AA
md5: e6bea5e321c1cfb20ea2248086ab8dda
name: E6BEA5E321C1CFB20EA2248086AB8DDA.mlw
sha1: 248a661fb2bb065fb24a3ba0af5edd99cc7c6dcf
sha256: 7e79e34e6a7db8e5ec924b1812cb2e7b9f3c13a0b8d8de52c22532a55cd61fef
sha512: cb9b2726d31a14c98d92a80691975c370b6d7aebaf74777543ad6edd8a0e6b3f2f062f016634643134fb8df1cceaf584bd788b075b9d9ca5a0ff55ed80e19a49
ssdeep: 3072:7kSXQC2mCN8SN7N4lxf5E/rkRm8mzM9i4G4hsb2rimITAqKbJhJiOY/gBR:gSS1oEYrjDsqriXKbJin/gj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.289154 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005337041 )
Elasticmalicious (high confidence)
DrWebBackDoor.Siggen2.2488
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGen:Variant.Zusy.289154
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005337041 )
Cybereasonmalicious.321c1c
CyrenW32/S-834d15b1!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GHJL
APEXMalicious
AvastFileRepMalware
ClamAVWin.Packer.Crypter-6539596-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.289154
NANO-AntivirusTrojan.Win32.NetWiredRc.fdpise
MicroWorld-eScanGen:Variant.Zusy.289154
TencentWin32.Backdoor.Netwire.Auto
Ad-AwareGen:Variant.Zusy.289154
SophosML/PE-A + Mal/GandCrab-D
ComodoTrojWare.Win32.PSW.Coins.GH@7ohrdk
BitDefenderThetaGen:NN.ZexaF.34628.lyW@aCxyPUpi
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_HPGen-37b
McAfee-GW-EditionBehavesLike.Win32.Trojan.cc
FireEyeGeneric.mg.e6bea5e321c1cfb2
EmsisoftGen:Variant.Zusy.289154 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1103318
MicrosoftRansom:Win32/GandCrab.AG!bit
AegisLabTrojan.Win32.Chapak.4!c
GDataWin32.Trojan.Kryptik.QP
AhnLab-V3Win-Trojan/Gandcrab02.Exp
Acronissuspicious
McAfeePacked-FGQ!E6BEA5E321C1
MAXmalware (ai score=98)
VBA32BScope.TrojanRansom.GandCrypt
MalwarebytesMalware.AI.1327112546
PandaTrj/Genetic.gen
TrendMicro-HouseCallMal_HPGen-37b
RisingDropper.Generic!8.35E (C64:YzY0OhnJURE8qemF)
YandexTrojan.GenAsa!IWwO5+OyUHA
IkarusTrojan.Win32.DNSChanger
MaxSecureRansomeware.CRAB.gen
FortinetW32/GenKryptik.CNAR!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HwoCEpsA

How to remove Zusy.289154?

Zusy.289154 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment