Malware

Ser.Zusy.2791 removal guide

Malware Removal

The Ser.Zusy.2791 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Zusy.2791 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Ser.Zusy.2791?


File Info:

name: A39BE1B580C1D03D5558.mlw
path: /opt/CAPEv2/storage/binaries/3f21e0b3ef80fd9393c6e187311a78aee22738f510ed227397249157b131b890
crc32: 81AD2920
md5: a39be1b580c1d03d5558d310ed429042
sha1: ef1556dabfd15e5da8f9128e1ed6e82d800a5256
sha256: 3f21e0b3ef80fd9393c6e187311a78aee22738f510ed227397249157b131b890
sha512: 3d76b0ecff0d90822b7081671b660d4982992a7a1a835b2cc5a4ef28993d8b8c450ab3d4ebbba15462da3a7677565f07b5163e18efb557e5bee6f04e0e757d90
ssdeep: 3072:CrnGUpuCbmOwlfnCcEWbaO8G/Kt1t91XnF5JzuEZa6K/vUtapMDBxzKB:Crn7p7bmO1AaWGt9B3JKEEPvMD/s
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F534C001F1E5C8B6E1A715308DB16A77D67EFE310B32869763D02B0E9D325D39926723
sha3_384: 86e73bbc6638bf4304dae2cb86c124e31c396d79b1a7e84d96d880f3df678d587a484a356cba26749fe06b0c2bda76f3
ep_bytes: 558bec6aff68e8564100683048400064
timestamp: 2018-12-18 12:29:14

Version Info:

Comments: Help user switch desk
CompanyName: Juxk
FileDescription: AWE
FileVersion: 7, 3, 2, 2
InternalName: PowCS
LegalCopyright: Copyright (C) 2018
LegalTrademarks:
OriginalFilename:
PrivateBuild:
ProductName: Moniw
ProductVersion: 6, 2, 5, 9
SpecialBuild:
Translation: 0x0409 0x04b0

Ser.Zusy.2791 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Daws.b!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ser.Zusy.2791
FireEyeGeneric.mg.a39be1b580c1d03d
McAfeeRDN/Generic Dropper
CylanceUnsafe
ZillyaDropper.Daws.Win32.14235
SangforTrojan.Win32.Occamy.C3F
K7AntiVirusTrojan ( 00543e131 )
AlibabaTrojanDropper:Win32/GenKryptik.9ba764f2
K7GWTrojan ( 00543e131 )
Cybereasonmalicious.580c1d
BitDefenderThetaGen:NN.ZexaF.34698.oq0@aezzTznj
CyrenW32/Chinoxy.C.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/GenKryptik.DIGU
TrendMicro-HouseCallTrojan.Win32.CHINOXY.ZBHI
Paloaltogeneric.ml
KasperskyTrojan-Dropper.Win32.Daws.eqvo
BitDefenderGen:Variant.Ser.Zusy.2791
NANO-AntivirusTrojan.Win32.Daws.fnrsxg
CynetMalicious (score: 99)
AvastWin32:Trojan-gen
TencentWin32.Trojan-Dropper.Daws.Sgil
Ad-AwareGen:Variant.Ser.Zusy.2791
TACHYONTrojan-Dropper/W32.Daws.237568.D
EmsisoftGen:Variant.Ser.Zusy.2791 (B)
ComodoMalware@#481v8m1puera
DrWebBackDoor.Chinoxy.2
VIPREGen:Variant.Ser.Zusy.2791
TrendMicroTrojan.Win32.CHINOXY.ZBHI
McAfee-GW-EditionBehavesLike.Win32.Emotet.dh
SophosMal/Generic-S
APEXMalicious
GDataGen:Variant.Ser.Zusy.2791
JiangminTrojanDropper.Daws.hvj
WebrootW32.Trojan.Gen
AviraTR/Drop.Daws.uqvft
Antiy-AVLTrojan/Generic.ASMalwS.258
ArcabitTrojan.Ser.Zusy.DAE7
ViRobotTrojan.Win32.Z.Daws.237568.A
MicrosoftTrojanDownloader:Win32/Emotet!ml
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C3274900
VBA32TrojanDropper.Daws
ALYacTrojan.Agent.Occamy.A
MAXmalware (ai score=85)
MalwarebytesMalware.AI.2882076640
RisingTrojan.Generic@AI.83 (RDML:dTbQfpYgcoww6I4T0IJYaQ)
YandexTrojan.GenAsa!5wMbNaJSPco
IkarusTrojan.Dropper.Daws
MaxSecureTrojan.Malware.74165353.susgen
FortinetW32/Daws.EQVO!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ser.Zusy.2791?

Ser.Zusy.2791 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment