Malware

Zusy.355468 removal

Malware Removal

The Zusy.355468 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.355468 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • Looks up the external IP address
  • Behavior consistent with a dropper attempting to download the next stage.
  • A process sent information about the computer to a remote location.

Related domains:

api.ipify.org
nuatanste.com
thircussovirom.ru
leffersinda.ru

How to determine Zusy.355468?


File Info:

crc32: 43928FF1
md5: 237b2a8f4a90edf5c94f75c647fbf035
name: 237B2A8F4A90EDF5C94F75C647FBF035.mlw
sha1: bd84a69528a247075e59b06f67fcff821f55e43f
sha256: 93557acc77e443c48e47bc3f1bda781c6584ff360fd4c0cccb797cd6e61f15b7
sha512: 4a6708d6155fab8b136da737f1f37fe692b5a6ccc285d1a653c53d102e0b18ca5d3525e227ceb2a24353cdaa456475c4b4930c582dab5a69513fbe2ad9f6f516
ssdeep: 3072:tZOwSfCEcb8E4Qd8ij7vyMQZei1Nv4IhAb+o+/tV:/byCE4899u7vyMezc
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Laystore Corporation. All rights reserved
InternalName: Far Piece
FileVersion: 5.2.3.505
CompanyName: Laystore Corporation
ProductName: Laystorexae Riverthenxae
ProductVersion: 5.2.3.505
FileDescription: Laystore Riverthen
OriginalFilename: Neck.dll
Translation: 0x0409 0x04b0

Zusy.355468 also known as:

DrWebTrojan.PWS.Siggen2.60824
MicroWorld-eScanGen:Variant.Zusy.355468
FireEyeGeneric.mg.237b2a8f4a90edf5
Qihoo-360Win32/Trojan.8a8
McAfeeRDN/Hancitor
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
BitDefenderGen:Variant.Zusy.355468
CyrenW32/Trojan.CSCO-5975
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HIER
TrendMicro-HouseCallTrojanSpy.Win32.DRIDEX.THLAOBO
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Banker.Win32.Cridex.gen
AlibabaTrojanBanker:Win32/Cridex.425e3194
Ad-AwareGen:Variant.Zusy.355468
SophosMal/Generic-S
F-SecureTrojan.TR/Banker.Cridex.rxfmb
TrendMicroTrojanSpy.Win32.DRIDEX.THLAOBO
McAfee-GW-EditionArtemis!Trojan
EmsisoftGen:Variant.Zusy.355468 (B)
IkarusTrojan-Banker.Cridex
WebrootW32.Trojan.Gen
AviraTR/Banker.Cridex.rxfmb
MAXmalware (ai score=81)
KingsoftWin32.Troj.Banker.(kcloud)
MicrosoftTrojan:Win32/Hancitor.AL!MTB
ArcabitTrojan.Zusy.D56C8C
ZoneAlarmHEUR:Trojan-Banker.Win32.Cridex.gen
GDataGen:Variant.Zusy.355468
CynetMalicious (score: 100)
ALYacTrojan.Agent.Hancitor
PandaTrj/CI.A
APEXMalicious
FortinetW32/Generik.FJUMFVN!tr
AVGFileRepMalware

How to remove Zusy.355468?

Zusy.355468 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment