Malware

Zusy.338144 malicious file

Malware Removal

The Zusy.338144 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.338144 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • A process was set to shut the system down when terminated
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

chetanh.zapto.org

How to determine Zusy.338144?


File Info:

crc32: 4EB8ECAE
md5: 307f5b20b319a15400f8ab37c6837a73
name: 307F5B20B319A15400F8AB37C6837A73.mlw
sha1: 1ca0aee1b0217998d0ffbd82c9524b0f543e65d4
sha256: 185e051eceb503bff8a336ac69a0bb4726363b33570bc1c0bb6ce17cb7346ec6
sha512: 19584e4b6c793a64e46ebc2d8750bcfb0e2d3b9569474d3ffd1bad008edd341c45ddd082986f45a2499ed2c5613fdc128f183e15f055233e248ce7c234c8c9cf
ssdeep: 6144:AfC2F8NXC794TB9vj48nklyq4HkyDX5Pcvsw8iJt9:AdeVQWTrvj4mkl8zD5EEK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.338144 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0053b4521 )
LionicTrojan.Win32.Generic.lBK8
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.8775
ClamAVWin.Packed.Bladabindi-7171769-0
CAT-QuickHealTrojanRansom.Blocker.A4
McAfeeBackDoor-FCEE!307F5B20B319
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.4914
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Zusy.338144
K7GWTrojan ( 0053b4521 )
Cybereasonmalicious.0b319a
CyrenW32/A-27762b68!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Bladabindi.L
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
AlibabaTrojan:MSIL/Bladabindi.21ea4bc2
NANO-AntivirusTrojan.Win32.Winlock.gbtnog
MicroWorld-eScanGen:Variant.Zusy.338144
Ad-AwareGen:Variant.Zusy.338144
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34142.qqW@a0qBnPi
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R06CC0PEJ21
FireEyeGeneric.mg.307f5b20b319a154
EmsisoftGen:Variant.Zusy.338144 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Patched.Ren.Gen
eGambitUnsafe.AI_Score_97%
MicrosoftBackdoor:Win32/Bladabindi!ml
SUPERAntiSpywareTrojan.Agent/Gen-GalPic
GDataGen:Variant.Zusy.338144
AhnLab-V3Trojan/Win32.Blocker.R126581
Acronissuspicious
VBA32Hoax.Blocker
MAXmalware (ai score=81)
MalwarebytesBackdoor.Bot
TrendMicro-HouseCallTROJ_GEN.R06CC0PEJ21
TencentWin32.Trojan.Generic.Lhnj
YandexTrojan.Blocker!RKagScXqN9E
IkarusBackdoor.MSIL
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.L!tr
PandaBck/Bladabindi.A

How to remove Zusy.338144?

Zusy.338144 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment