Malware

Zusy.344415 (file analysis)

Malware Removal

The Zusy.344415 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.344415 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to modify desktop wallpaper
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Writes a potential ransom message to disk
  • EternalBlue behavior
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Generates some ICMP traffic
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

api.blockcypher.com
btc.blockr.io

How to determine Zusy.344415?


File Info:

crc32: 561F7684
md5: b9e818a672d02acc7548b2456a112b44
name: B9E818A672D02ACC7548B2456A112B44.mlw
sha1: 1155cdf04a0a98becc5fd6da8d16e578936a8e3b
sha256: 9bdbbabf543a7656a5f03c213d58ae62a36fdd1da63b72ff1cb2a9d8c1bd0298
sha512: d09f19de44fa0ba6be438dddfb13c1fc9638f980b47ffc61dbadbd033921a3a8623e6529638f52d9427b4175c6e664aba5ccfb108b7ccb916f6d96137d0b18b5
ssdeep: 3072:tiCw9E+PtjruCro8Km63q7IUU6ssKgxHf3c8QxDozWE2NKGJgPLMr3B5KUpMDGF:tiCF8KDqkUU+FDQxDgPGJvPKUpyGF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompanyName: Ghisler Software GmbH
Translation: 0x0409 0x0000

Zusy.344415 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005224381 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
ClamAVWin.Ransomware.Cerber-7649513-1
CAT-QuickHealRansom.Cerber.A4
ALYacGen:Variant.Zusy.344415
CylanceUnsafe
ZillyaTrojan.GenKryptik.Win32.6771
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 005224381 )
Cybereasonmalicious.672d02
CyrenW32/Cerbern.AMAD-2642
SymantecPacked.Generic.459
ESET-NOD32Win32/Filecoder.Cerber.G
ZonerTrojan.Win32.58899
APEXMalicious
AvastWin32:Dropper-gen [Drp]
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Zerber.eddk
BitDefenderGen:Variant.Zusy.344415
NANO-AntivirusTrojan.Win32.Zerber.epeyiy
ViRobotTrojan.Win32.Cerber.296448
MicroWorld-eScanGen:Variant.Zusy.344415
TencentMalware.Win32.Gencirc.10ba7125
Ad-AwareGen:Variant.Zusy.344415
SophosMal/Generic-R + Mal/Cerber-B
BitDefenderThetaGen:NN.ZexaF.34790.sq0@augMO@x
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroRansom_HPCERBER.SMALY5A
McAfee-GW-EditionBehavesLike.Win32.Dropper.dh
FireEyeGeneric.mg.b9e818a672d02acc
EmsisoftGen:Variant.Zusy.344415 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Zerber.ccu
AviraHEUR/AGEN.1134602
eGambitUnsafe.AI_Score_87%
Antiy-AVLTrojan/Generic.ASMalwS.2055B12
MicrosoftRansom:Win32/Cerber.K
SUPERAntiSpywareRansom.Cerber/Variant
GDataGen:Variant.Zusy.344415
TACHYONRansom/W32.Cerber.296448
AhnLab-V3Win-Trojan/Cerber.Exp
Acronissuspicious
McAfeeRansomware-GCQ!B9E818A672D0
MAXmalware (ai score=85)
VBA32BScope.Trojan-Ransom.Zerber
MalwarebytesRansom.Cerber
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPCERBER.SMALY5A
RisingTrojan.Kryptik!1.AD41 (CLASSIC)
YandexTrojan.GenAsa!iXPco+IUVWE
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.HGZD!tr
AVGWin32:Dropper-gen [Drp]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cerber.HxQBaTcA

How to remove Zusy.344415?

Zusy.344415 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment