Malware

Should I remove “Ser.Zusy.2528”?

Malware Removal

The Ser.Zusy.2528 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Zusy.2528 virus can do?

  • Executable code extraction
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Steals private information from local Internet browsers
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
freekzvideo.cloud

How to determine Ser.Zusy.2528?


File Info:

crc32: ABDA5179
md5: 18b03f8cc2b94d5587749be95a443b33
name: id1.exe
sha1: 6ed9fde9092216855ed679e941ccd64eb98e2220
sha256: 423b9b40cbf0a308dec5feca70671ab44632c706e71b76e9aadf73ae6d2a09a2
sha512: 887d85ebada2b0ce3a66b2a5fabf0160845fb7a77a1a9f5794b2390c1a73205556c385ca21112cf099e4147b971563e17f1ff413b274fa3ab5ea41eef04c92c7
ssdeep: 24576:RtAdtYWzaiyc2iv1a8vtdwt2XuxdwNmkZ84tFDOsoefAgbyM5czl:RSdtYc/FVdo2XKyX7LfAg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: CorpRight(C) 2020
InternalName: Main
FileVersion: 1, 0, 0,2
CompanyName: Microsoft Corporation
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Microsoft Corporation Main
SpecialBuild:
ProductVersion: 1, 0, 0, 2
FileDescription: Teamviewer Config
OriginalFilename: Config.exe
Translation: 0x0804 0x04b0

Ser.Zusy.2528 also known as:

DrWebTrojan.PWS.Spy.21448
MicroWorld-eScanGen:Variant.Ser.Zusy.2528
FireEyeGeneric.mg.18b03f8cc2b94d55
ALYacGen:Variant.Ser.Zusy.2528
MalwarebytesSpyware.Socelars
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Zusy.4!c
SangforMalware
K7AntiVirusTrojan ( 005189531 )
BitDefenderGen:Variant.Ser.Zusy.2528
K7GWTrojan ( 005189531 )
Cybereasonmalicious.909221
BitDefenderThetaGen:NN.ZexaF.34122.4r0@aaHFPEeb
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
GDataGen:Variant.Ser.Zusy.2528
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/Kryptik.89292299
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareGen:Variant.Ser.Zusy.2528
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.Agent.fxpmw
BaiduWin32.Trojan.Farfli.bc
McAfee-GW-EditionBehavesLike.Win32.Generic.th
EmsisoftGen:Variant.Ser.Zusy.2528 (B)
AviraTR/Crypt.Agent.fxpmw
Antiy-AVLTrojan/Win32.Pynamer
Endgamemalicious (high confidence)
ArcabitTrojan.Ser.Zusy.D9E0
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Trojan/Win32.Infostealer.C4075542
MAXmalware (ai score=88)
VBA32suspected of Trojan.Downloader.gen.h
CylanceUnsafe
ESET-NOD32a variant of Win32/Kryptik.HCXM
TrendMicro-HouseCallTROJ_GEN.R002H09EP20
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/GenKryptik.EFRL!tr
AVGWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.fc8

How to remove Ser.Zusy.2528?

Ser.Zusy.2528 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment