Malware

Zusy.348569 removal guide

Malware Removal

The Zusy.348569 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.348569 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Sorbian
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

ecosystem.unvocal.ru
duckandbear.top
www.bing.com

How to determine Zusy.348569?


File Info:

crc32: 1F1B959C
md5: 07a08d77def4260505617287ee502c6c
name: 07A08D77DEF4260505617287EE502C6C.mlw
sha1: 886e8c2d5b6755cfdc6e26e48777029165087faa
sha256: ddf85870f2dbb65b47e167cc3eea15c29b8c58e40614b88996116f475307ddb6
sha512: ce31ba69ebee110bd447646069cf6925cbc206a8ae68aa6024f3619afa81aaab0bdf5ac13f91b52169a4bc274bf0982b062ac934ffaa35e0daa5dfe67304f732
ssdeep: 6144:IqzR5Xj8aScm223T9phmKk7Yva1B1oVsWOA0:IqzR98aVm22j9CtQa1UnOA0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: iDiego
InternalName: iDiego
FileVersion: 1.4.30.21
CompanyName: iDiego
ProductName: iDiego
ProductVersion: 4.0.0.1
FileDescription: iDiego
OriginalFilename: iDiego
Translation: 0x0400 0x04b0

Zusy.348569 also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
DrWebTrojan.InstallMonster.2347
MicroWorld-eScanGen:Variant.Zusy.348569
FireEyeGeneric.mg.07a08d77def42605
CAT-QuickHealAdware.Dataric.A5
McAfeePUP-GKK
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabRiskware.Win32.Generic.1!c
SangforMalware
K7AntiVirusTrojan-Downloader ( 005162a01 )
BitDefenderGen:Variant.Zusy.348569
K7GWTrojan-Downloader ( 005162a01 )
Cybereasonmalicious.7def42
BitDefenderThetaAI:Packer.074D86921F
CyrenW32/S-a04dfd80!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastFileRepMalware
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
NANO-AntivirusTrojan.Win32.Zenpak.fvgtpk
RisingDownloader.Tovkater!8.E5CE (CLOUD)
Ad-AwareGen:Variant.Zusy.348569
EmsisoftApplication.InstallMon (A)
ComodoApplicUnwnt@#1f0nsuhxr237f
F-SecureAdware.ADWARE/InstMonster.Gen7
McAfee-GW-EditionBehavesLike.Win32.Generic.tz
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Tovkater
GDataGen:Variant.Zusy.348569
JiangminAdWare.Generic.ipeo
AviraADWARE/InstMonster.Gen7
Antiy-AVLGrayWare[AdWare]/Win32.TOVus
ArcabitTrojan.Zusy.D55199
SUPERAntiSpywarePUP.InstallMonster/Variant
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Generic
MicrosoftProgram:Win32/Wacapew.C!ml
CynetMalicious (score: 85)
AhnLab-V3PUP/Win32.Amonetize.R208783
VBA32Trojan.InstallMonster
ALYacGen:Variant.Zusy.348569
MAXmalware (ai score=84)
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/TrojanDownloader.Tovkater.CT
TencentMalware.Win32.Gencirc.10b4585c
YandexTrojan.GenAsa!S8Sd3w0lFd8
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/Tovkater.CQ!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Virus.Adware.b51

How to remove Zusy.348569?

Zusy.348569 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment