Malware

Zusy.337808 removal instruction

Malware Removal

The Zusy.337808 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.337808 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

www.a5D64EdVYX.com
zipansion.com
aporasal.net

How to determine Zusy.337808?


File Info:

crc32: E5EABA61
md5: 457ed3a2234d1056533562d34202d98c
name: 457ED3A2234D1056533562D34202D98C.mlw
sha1: e430d93a076cf0b1ef103e1c0fa6a62966b35ded
sha256: e9b4f9e3941fc2acff85b45ed53e1553ddb1d549de73a871f53b4829928ef530
sha512: a837d142c05821334a93f6a1afeefb63a59e767a16f7a0e8a3ecdaea6173eabe1ecf59df88a4872c2db98a6dbd3e9553391ab2327da36a43b2c87cb59da45d00
ssdeep: 3072:Q7a14dZO89lJzGoPqOHXPvf3SAev+woAnYiM0xZ10G+qad/o74/TegUt1uPJCiww:Q7a1OOmCqjevRXMQn96/oKDU2PQGdzX
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Zusy.337808 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.337808
FireEyeGeneric.mg.457ed3a2234d1056
CAT-QuickHealTrojan.Generic
McAfeeGenericRXAA-FA!457ED3A2234D
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 0056e8c71 )
BitDefenderGen:Variant.Zusy.337808
K7GWTrojan ( 0056e8c71 )
Cybereasonmalicious.2234d1
CyrenW32/Kryptik.CWV.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Generic.4f36712c
RisingTrojan.Kryptik!1.D12D (CLASSIC)
Ad-AwareGen:Variant.Zusy.337808
SophosMal/Generic-S
ComodoMalware@#1uzir45715krb
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WAR21
McAfee-GW-EditionBehavesLike.Win32.VirRansom.dc
EmsisoftGen:Variant.Zusy.337808 (B)
IkarusTrojan.Win32.Injector
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Injector
MicrosoftTrojan:Win32/Ymacco.AAE9
ArcabitTrojan.Zusy.D52790
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Zusy.337808
AhnLab-V3Trojan/Win32.Skeeyah.C2863900
BitDefenderThetaGen:NN.ZexaF.34804.piW@a02nYOg
ALYacGen:Variant.Zusy.337808
VBA32BScope.Trojan.Wacatac
MalwarebytesMachineLearning/Anomalous.95%
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.DZQA
TrendMicro-HouseCallTROJ_GEN.R002C0WAR21
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.FFP!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Trojan.Generic.HxMB6ocA

How to remove Zusy.337808?

Zusy.337808 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment