Malware

Zusy.348765 removal

Malware Removal

The Zusy.348765 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.348765 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • The binary likely contains encrypted or compressed data.
  • Steals private information from local Internet browsers
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Harvests credentials from local FTP client softwares
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

sbershit.com
ip-api.com

How to determine Zusy.348765?


File Info:

crc32: 575F3131
md5: 9d21135f20ba70dfa9bbb0a8556e1903
name: 9D21135F20BA70DFA9BBB0A8556E1903.mlw
sha1: 3ff2efbe1363b5b1d850fac83d1601bb7fd24e3f
sha256: cd97b38bd1b1fa2665ab13c29560a206f15ce023931cad623e172d65d60d742e
sha512: b3fa284c01f7b2b31f8014b30b04e33d39e9da81868221b7c7fe59934ef6c10de14d63c12dedf6697a7093fc74379576952f322bd1cfb5b625705dace9a4d258
ssdeep: 12288:FnNQwdIsyXErot7kApgzZNAZP101WIYvt9RT:F9tIuVNAZWYvtrT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: driveapoges.ots
FileVers: 26.26.361
Copyright: Copyrighz (C) 2020, pipkafug
TranslationUsa: 0x0471 0x011c

Zusy.348765 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.348765
CAT-QuickHealTrojan.Agent
ALYacGen:Variant.Zusy.348765
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Agent.4!c
SangforMalware
K7AntiVirusTrojan ( 00573bf11 )
BitDefenderGen:Variant.Zusy.348765
K7GWTrojan ( 00573bf11 )
Cybereasonmalicious.e1363b
CyrenW32/RanumBot.H.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HHST
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Tofsee-9801241-0
KasperskyHEUR:Trojan.Win32.Agent.gen
AlibabaTrojan:Win32/Glupteba.335a245b
ViRobotTrojan.Win32.Z.Zusy.617984.Z
Ad-AwareGen:Variant.Zusy.348765
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.Agent.iruse
DrWebTrojan.Siggen11.48980
TrendMicroTrojan.Win32.GLUPTEBA.THKCOBO
McAfee-GW-EditionBehavesLike.Win32.Gupboot.jh
FireEyeGeneric.mg.9d21135f20ba70df
EmsisoftGen:Variant.Zusy.348765 (B)
IkarusTrojan.Win32.Ranumbot
JiangminExploit.ShellCode.aqs
eGambitUnsafe.AI_Score_81%
AviraTR/Crypt.Agent.iruse
Antiy-AVLTrojan[Backdoor]/Win32.Tofsee
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Glupteba.ML!MTB
ArcabitTrojan.Zusy.D5525D
AhnLab-V3Trojan/Win32.Glupteba.R356680
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
GDataGen:Variant.Zusy.348765
CynetMalicious (score: 100)
Acronissuspicious
McAfeeRDN/Generic Dropper
MAXmalware (ai score=83)
VBA32Trojan.Glupteba
MalwarebytesTrojan.MalPack.GS
PandaTrj/RnkBend.A
TrendMicro-HouseCallTrojan.Win32.GLUPTEBA.THKCOBO
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HHUN!tr
WebrootW32.Trojan.Gen
AVGWin32:DropperX-gen [Drp]
AvastWin32:DropperX-gen [Drp]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/HEUR/QVM10.2.81FF.Malware.Gen

How to remove Zusy.348765?

Zusy.348765 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment