Malware

Zusy.343267 removal guide

Malware Removal

The Zusy.343267 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.343267 virus can do?

  • Creates RWX memory
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Checks for the presence of known windows from debuggers and forensic tools
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.343267?


File Info:

crc32: 8F54E1B2
md5: 1844ee9774d154452bbc3ea9cd6e6871
name: 1844EE9774D154452BBC3EA9CD6E6871.mlw
sha1: 777d482cb449fc7cf71938a52918ed34db2b64e0
sha256: 03398177e85151abbaed12718ad54b7226d2079244966a87d092bca9d2cb5b4d
sha512: e3ef7bd054f0a1a53831d7df5c1e71091f28bc50679f846467f04d9fd5b61c2da7d843373ec13db6a54fdeb6ed5c7c8840c7be9a404e7d5cfc5b0e06ab3b983f
ssdeep: 98304:i/vWclby+rwOroIABYHFR83sndg3T1TzTgTTuTIT2TvTk0+TM9m8YV359lhX5:i/vWcdoI3R+sdBMIMM359z
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: www.GameModding.net
InternalName:
FileVersion: 3.1.0.0
CompanyName: www.GameModding.net
LegalTrademarks:
Comments:
ProductName: ModInstall
ProductVersion: 1.0.0.0
FileDescription: ModInstall 3.0
OriginalFilename:
Translation: 0x0419 0x04e3

Zusy.343267 also known as:

K7AntiVirusAdware ( 005693e61 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.343267
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWAdware ( 005693e61 )
Cybereasonmalicious.774d15
CyrenW32/GameModding.G.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/GameModding.C potentially unwanted
APEXMalicious
AvastFileRepMetagen [Malware]
ClamAVWin.Malware.Gamemodding-6956227-0
BitDefenderGen:Variant.Zusy.343267
MicroWorld-eScanGen:Variant.Zusy.343267
Ad-AwareGen:Variant.Zusy.343267
SophosGeneric PUA HH (PUA)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.rh
FireEyeGeneric.mg.1844ee9774d15445
EmsisoftGen:Variant.Zusy.343267 (B)
SentinelOneStatic AI – Malicious PE
AviraPUA/GameModding.Gen
Antiy-AVLTrojan/Generic.ASMalwS.235F361
MicrosoftTrojan:Win32/Wacatac.A!ml
ArcabitTrojan.Zusy.D53CE3
GDataWin32.Application.GameModding.A
AhnLab-V3PUP/Win32.Helper.R222668
Acronissuspicious
McAfeeGenericRXDN-SN!1844EE9774D1
MAXmalware (ai score=96)
VBA32BScope.Adware.Downware
MalwarebytesRiskWare.GameHack
PandaTrj/CI.A
RisingTrojan.Generic@ML.100 (RDML:hDMQHVBiZuyH14bQ9jqCPQ)
YandexTrojan.GenAsa!ZOhp4HR2QgA
IkarusPUA.GameModding
MaxSecureAdware.GameModding.a
FortinetW32/GameModding.C!tr
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml

How to remove Zusy.343267?

Zusy.343267 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment