Malware

Ser.Zusy.4178 (B) removal guide

Malware Removal

The Ser.Zusy.4178 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Zusy.4178 (B) virus can do?

  • Sample contains Overlay data
  • HTTPS urls from behavior.
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Uses Windows utilities to create a scheduled task
  • Attempts to identify installed AV products by installation directory
  • Attempts to modify proxy settings
  • Appears to use command line obfuscation
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Ser.Zusy.4178 (B)?


File Info:

name: D9691EE85CC32FF9B36C.mlw
path: /opt/CAPEv2/storage/binaries/2ddd4837ee68e741fd262468000811ff52b968aaff0ddec9d124f0dec379d481
crc32: 468D6DF3
md5: d9691ee85cc32ff9b36c47fd9ae7d850
sha1: 2e939bce3921abe4329e69e5ee759b17bcad2487
sha256: 2ddd4837ee68e741fd262468000811ff52b968aaff0ddec9d124f0dec379d481
sha512: 090a827fbb4d174fb5e6d831f14967799f118628f0f305706262e46cc47832dc2efe3cf2dc2771756ebd37c7840bed550cd0a409dab21e4d209a366401c3e646
ssdeep: 3072:3vtV3ROZ6RDwrR3wMUzUVwQ3rInyRnIvPak3hhiHFSbuZhuNcZVKBzqm8LHIkbGB:ftV3euVz6rKyS3yHFHhuNcPKpwU+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D72408557812C032D56061762DB5BFF2C59DA828ABB049DB7B800F77DA112F73A70E3A
sha3_384: 0bbc9d0e12e8a6972ac64fa8d366eda0c65d63d9047562f587dced00db8252db17b8725d1517bc18674838904d1141d2
ep_bytes: e884040000e974feffffe9ac41000055
timestamp: 2023-07-24 12:21:28

Version Info:

0: [No Data]

Ser.Zusy.4178 (B) also known as:

BkavW32.AIDetectMalware
ElasticWindows.Trojan.Amadey
DrWebTrojan.DownLoader45.62430
MicroWorld-eScanGen:Variant.Ser.Zusy.4178
ClamAVWin.Malware.Doina-10001799-0
FireEyeGeneric.mg.d9691ee85cc32ff9
ALYacGen:Variant.Ser.Zusy.4178
Cylanceunsafe
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.85cc32
BitDefenderThetaAI:Packer.2CDFB55E1F
CyrenW32/Amadey.C1.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/TrojanDownloader.Amadey.A
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Variant.Ser.Zusy.4178
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Variant.Ser.Zusy.4178 (B)
F-SecureHeuristic.HEUR/AGEN.1317762
VIPREGen:Variant.Ser.Zusy.4178
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
Trapminesuspicious.low.ml.score
IkarusTrojan-Downloader.Win32.Amadey
GDataGen:Variant.Ser.Zusy.4178
JiangminTrojanDownloader.Deyma.aqt
AviraHEUR/AGEN.1317762
ArcabitTrojan.Ser.Zusy.D1052
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
MicrosoftTrojan:Win32/Amadey.RPX!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Amadey.C5459518
McAfeeDownloader-FCND!D9691EE85CC3
MAXmalware (ai score=84)
PandaTrj/Genetic.gen
RisingDownloader.Amadey!8.125AC (TFE:5:RZlUpeBEt9L)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Amadey.A!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Ser.Zusy.4178 (B)?

Ser.Zusy.4178 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment