Malware

What is “Zusy.337449”?

Malware Removal

The Zusy.337449 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.337449 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A process created a hidden window
  • Creates a hidden or system file
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
i.imgur.com

How to determine Zusy.337449?


File Info:

crc32: 79E4903C
md5: 4be1bc0d4811a66a056fd6fe84205134
name: 4BE1BC0D4811A66A056FD6FE84205134.mlw
sha1: 54395ce9dc76b798b9052c33e2c92184832a2e75
sha256: 452daf183846078dffb7fb5595860656cbff08f53bf710dd33c17590e2f13177
sha512: 14d3b9a83fcb46acc4e5a59538435c510d16dcc6e40efe529d3159fd2119efc34c5681399d9b20ad07845300a01c1601b25c436002297c4542864fae38c48cdf
ssdeep: 24576:P7HUgE+h6PyUHQB+3F3bNXEBJO85qUmAYz4bUPBrXNbBbjL:/B6PyUH3LGm6FXkr9bl
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 4.2.2.2
CompanyName: Samsung
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.0.0
FileDescription: SamsungCorperation
OriginalFilename:
Translation: 0x0409 0x04e4

Zusy.337449 also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Zusy.337449
FireEyeGen:Variant.Zusy.337449
McAfeeArtemis!4BE1BC0D4811
BitDefenderGen:Variant.Zusy.337449
SymantecML.Attribute.HighConfidence
APEXMalicious
NANO-AntivirusExploit.Win32.Shellcode.iatbze
Ad-AwareGen:Variant.Zusy.337449
EmsisoftGen:Variant.Zusy.337449 (B)
DrWebBackDoor.Rat.281
McAfee-GW-EditionArtemis
SentinelOneStatic AI – Suspicious PE
JiangminExploit.ShellCode.and
MaxSecureTrojan.Malware.74214920.susgen
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Wacatac.C!ml
ArcabitTrojan.Zusy.D52629
GDataGen:Variant.Zusy.337449
BitDefenderThetaGen:NN.ZexaF.34634.qH0@a8kIbHji
ALYacGen:Variant.Zusy.337449
VBA32BScope.Backdoor.Remcos
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/GenKryptik.EUCV
RisingTrojan.GenKryptik!8.AA55 (TFE:5:CLZ7dBCuFBN)
IkarusTrojan.NsisInject
FortinetW32/Rugmi.FAH!tr.dldr
AVGFileRepMalware

How to remove Zusy.337449?

Zusy.337449 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment