Malware

Zusy.343418 removal guide

Malware Removal

The Zusy.343418 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.343418 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Loads a driver
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Queries information on disks, possibly for anti-virtualization
  • Installs itself for autorun at Windows startup
  • Checks the version of Bios, possibly for anti-virtualization
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

holl.f3322.net

How to determine Zusy.343418?


File Info:

crc32: F31DA03C
md5: aeb4798820d681ce15d9417af2edf573
name: AEB4798820D681CE15D9417AF2EDF573.mlw
sha1: 2547135d67cb00f482e27f32becdbf897f8a83ae
sha256: 5a85b879fefa95e95581ae19e4f2ae61c4b1e2bc6666b81ca671622c03b0744d
sha512: 7de534a376b886b4536fae6f9b7f5da0722d9694c52fe5d2abbc2cef1f1beb7aade89d1dc9daa775fc412c4909208d1bc5d261f2612be0369e3fa7714c2908df
ssdeep: 24576:SKRvi4PSK9vht6Xo+4bb6OlDf9SzKeazIZw9BAAmD6nJTvQNswtuoZRD:NdKg5tUEb6OlZ8kzIZHKl2swoCRD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.343418 also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.343418
FireEyeGeneric.mg.aeb4798820d681ce
CAT-QuickHealTrojan.Generic
McAfeeTrojan-FDFO!AEB4798820D6
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 004b95821 )
AlibabaBackdoor:Win32/NoobyProtect.9c425b80
K7GWTrojan ( 004b95821 )
Cybereasonmalicious.d67cb0
BitDefenderThetaGen:NN.ZexaF.34670.vrW@ammPY1l
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0PL320
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.343418
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
Paloaltogeneric.ml
RisingTrojan.Generic@ML.100 (RDML:rJq9ibOX+vwMBJL2Li1+1w)
Ad-AwareGen:Variant.Zusy.343418
SophosMal/Generic-S
ComodoTrojWare.Win32.Amtar.KNB@4wlm66
F-SecureHeuristic.HEUR/AGEN.1103508
DrWebTrojan.Siggen11.52567
TrendMicroTROJ_GEN.R002C0PL320
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SentinelOneStatic AI – Suspicious PE
EmsisoftGen:Variant.Zusy.343418 (B)
APEXMalicious
GDataGen:Variant.Zusy.343418
AviraHEUR/AGEN.1103508
MAXmalware (ai score=86)
GridinsoftTrojan.Heur!.030180A1
ArcabitTrojan.Zusy.D53D7A
AegisLabTrojan.Win32.Generic.lYHq
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Zegost.EG!bit
CynetMalicious (score: 100)
Acronissuspicious
VBA32BScope.Backdoor.Farfli
ESET-NOD32a variant of Win32/Packed.NoobyProtect.B suspicious
TencentWin32.Trojan.Generic.Lqym
FortinetW32/SfEngine.A!tr
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Zusy.343418?

Zusy.343418 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment