Malware

Zusy.354991 removal

Malware Removal

The Zusy.354991 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.354991 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

telete.in
apps.identrust.com
tripsafe.fun

How to determine Zusy.354991?


File Info:

crc32: 97C366FF
md5: 451c01146bf6d0075d41ee9034f2059a
name: 451C01146BF6D0075D41EE9034F2059A.mlw
sha1: 54644c8488c37287e2e897c444a74e55f405ee22
sha256: 0fd1106af0b985ea7293672c9d0d900b2f32fb93645b6be04b3fc1e2521323be
sha512: c6cc772ed60a6840f0a8caf89356bcc52997ae3979c471ccc9af0476a7fb2a7bc859b08389a55f43418e77d7d46fd2c95fc6fef8655940a5ab319170599b5570
ssdeep: 6144:dI2rNtaGLNmToZ5xDbhjK+EWeioSdV9PkI+ynKCgGm0Emn7M96Jqu+FrnTdA2wT:dI2RtPYTA5xhIdXcVRiBA7M9zrT3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

InternalName: triwerbikis.acs
FileVers: 26.26.361
ProductionVersion: 1.0.22.25
Copyright: Copyrighz (C) 2020, podkafux
TranslationUsa: 0x8712 0x009e

Zusy.354991 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.354991
FireEyeGeneric.mg.451c01146bf6d007
ALYacGen:Variant.Zusy.354991
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005744ef1 )
BitDefenderGen:Variant.Zusy.354991
K7GWTrojan ( 005744ef1 )
Cybereasonmalicious.488c37
CyrenW32/Kryptik.CRA.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Trojan.Win32.Zenpak.gen
Ad-AwareGen:Variant.Zusy.354991
EmsisoftTrojan.Crypt (A)
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Glupteba.NG!MTB
ArcabitTrojan.Zusy.D56AAF
ZoneAlarmHEUR:Trojan.Win32.Zenpak.gen
GDataWin32.Trojan.PSE.ESD9N4
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Glupteba.R357616
Acronissuspicious
McAfeeGenericRXMW-RU!451C01146BF6
VBA32BScope.Trojan.Glupteba
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.HIDE
RisingTrojan.Kryptik!8.8 (TFE:5:1pAR0ys8lDU)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.ERHN!tr
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM10.1.DA04.Malware.Gen

How to remove Zusy.354991?

Zusy.354991 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment