Malware

What is “Zusy.347909”?

Malware Removal

The Zusy.347909 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.347909 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Zusy.347909?


File Info:

crc32: EF4F7036
md5: 2ef8d4f584dc562bd8b911074ed8c3a0
name: 2EF8D4F584DC562BD8B911074ED8C3A0.mlw
sha1: dcd0ab2703867905478573c88464fa85a72dfd13
sha256: c7d2763c845a08a22775c242be4368bbad967ae4d2f82be1042645d6a70320a5
sha512: 423fa5a90a530bba778d0df3ac5e2386140c621194a104be47c0d7b8603f5ed28789e666a94b793019aa3830e28db88c79a408b7b1d31817656322365c1e16d4
ssdeep: 49152:b3D7H4a7GMWeWEFKmOZFuvQaZVhlZfyiSCyiSV/CznFw9:b3nYSWeWEFKmOZFqQaZVLpi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1998-2017 Mark Russinovich
InternalName: Process Explorer
FileVersion: 16.21
CompanyName: Sysinternals - www.sysinternals.com
LegalTrademarks: Copyright (C) 1998-2017 Mark Russinovich
ProductName: Process Explorer
ProductVersion: 16.21
FileDescription: Sysinternals Process Explorer
OriginalFilename: Procexp.exe
Translation: 0x0409 0x04e4

Zusy.347909 also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.347909
FireEyeGeneric.mg.2ef8d4f584dc562b
McAfeeArtemis!2EF8D4F584DC
CylanceUnsafe
K7AntiVirusVirus ( 7000000f1 )
BitDefenderGen:Variant.Zusy.347909
K7GWVirus ( 7000000f1 )
BitDefenderThetaGen:NN.ZelphiF.34634.dI3@amMVA@ki
CyrenW32/Bulz.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AlibabaTrojanDownloader:Win32/Injector.2620da2a
ViRobotTrojan.Win32.Z.Bulz.2160240
Ad-AwareGen:Variant.Zusy.347909
EmsisoftGen:Variant.Zusy.347909 (B)
F-SecureTrojan.TR/Injector.okszd
McAfee-GW-EditionArtemis!Trojan
IkarusTrojan.Inject
AviraTR/Injector.okszd
MicrosoftTrojan:Win32/Wacatac.C!ml
ArcabitTrojan.Jacard.D32191
GDataGen:Variant.Zusy.347909
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R347077
VBA32BScope.Trojan.Downloader
ALYacGen:Variant.Bulz.49339
MAXmalware (ai score=87)
MalwarebytesTrojan.MalPack.SMY
ZonerTrojan.Win32.98768
ESET-NOD32Win32/TrojanDownloader.Delf.DCB
TrendMicro-HouseCallTROJ_GEN.R06CH09KN20
SentinelOneStatic AI – Suspicious PE
FortinetW32/Injector.ENYP!tr
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (D)
Qihoo-360Generic/Trojan.b75

How to remove Zusy.347909?

Zusy.347909 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment