Malware

Zusy.348814 (B) (file analysis)

Malware Removal

The Zusy.348814 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.348814 (B) virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
discord.com
cdn.discordapp.com

How to determine Zusy.348814 (B)?


File Info:

crc32: C95E7602
md5: 9d806e69205f73a455806ca69e753fdb
name: 9D806E69205F73A455806CA69E753FDB.mlw
sha1: e759c0c4cc5bd2ab962b6a3765f984441d9120c9
sha256: 88cd6b3cae21bbdf028d5fee94c3552ecc427043b70b8407e9f936857c637ee5
sha512: b59970b7333e8879ca867823dea4ee086cfed7adbe8f5c4663131307fe8323165c0a487709fe3283c3c9f30584585c20e5d292c282442a277048585797814e14
ssdeep: 24576:DLHLdu/OaH5JS1H6OkN5HYybB68gKmX9hIbEIKF:DLrd08kN5HYYRgKAh
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.348814 (B) also known as:

MicroWorld-eScanGen:Variant.Zusy.348814
FireEyeGeneric.mg.9d806e69205f73a4
McAfeeFareit-FZO!9D806E69205F
CylanceUnsafe
BitDefenderGen:Variant.Zusy.348814
SymantecML.Attribute.HighConfidence
APEXMalicious
AlibabaTrojan:Win32/Fareit.408da453
Ad-AwareGen:Variant.Zusy.348814
EmsisoftGen:Variant.Zusy.348814 (B)
McAfee-GW-EditionFareit-FZO!9D806E69205F
IkarusTrojan.Inject
MAXmalware (ai score=84)
MicrosoftPWS:Win32/Fareit!ml
ArcabitTrojan.Zusy.D5528E
GDataGen:Variant.Zusy.348814
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZelphiF.34658.kHY@aK7qXxii
VBA32BScope.Trojan.Diple
MalwarebytesTrojan.MalPack.SMY.Generic
TrendMicro-HouseCallTROJ_GEN.R06CH0CKQ20
SentinelOneStatic AI – Suspicious PE
eGambitPE.Heur.InvalidSig
FortinetW32/GenKryptik.DPIE!tr
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Zusy.348814 (B)?

Zusy.348814 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment