Malware

Zusy.135070 (B) removal instruction

Malware Removal

The Zusy.135070 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.135070 (B) virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates a hidden or system file
  • Uses suspicious command line tools or Windows utilities

Related domains:

www.bing.com
maktoob.yahoo.com

How to determine Zusy.135070 (B)?


File Info:

crc32: 90070C86
md5: 44b5a3af895f31e22f6bc4eb66bd3eb7
name: a98099541168c7f36b107e24e9c80c9125fefb787ae720799b03bb4425aba1a9
sha1: 2e7e2bc0b92f4c4f095a04a785e2b08d3666883b
sha256: a98099541168c7f36b107e24e9c80c9125fefb787ae720799b03bb4425aba1a9
sha512: 6efdf1581ec90867c243b99dcaf08a3a8b306582686eb3d79bf52d4e12febcd3ec50c91fa98e32f5496d9724e677454f41ec9cb39548ec95c5764ddeca8a00ac
ssdeep: 6144:+W/434pHIXYWtsWLxiG5w6f1uBjE/yFfpU8nrs0T/ihAOt:+73gIPLxiG5w6oBjn28npTrS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: rundll32.exe
FileVersion: 2, 0, 0, 2
CompanyName: Microsoft Corporation
SpecialBuild: 2, 0, 0, 2
Comments: Windows Help Service
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 2, 0, 0, 2
FileDescription: Windows Help Service
OriginalFilename: rundll32.exe
Translation: 0x0409 0x04b0

Zusy.135070 (B) also known as:

BkavW32.EncapterLTQ.Trojan
MicroWorld-eScanGen:Variant.Zusy.135070
FireEyeGeneric.mg.44b5a3af895f31e2
CAT-QuickHealTrojanDropper.Dycler
McAfeeGeneric.dgg
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 004bbd201 )
BitDefenderGen:Variant.Zusy.135070
K7GWTrojan ( 004bbd201 )
Cybereasonmalicious.f895f3
TrendMicroBKDR_EXPLOSIVE.A
SymantecTrojan.Explod!g1
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Explosive-6479674-0
AlibabaWorm:Win32/Dycler.366f41cd
NANO-AntivirusTrojan.Win32.Dycler.dpzase
ViRobotTrojan.Win32.Explosive.357315
AegisLabTrojan.Win32.Dycler.tpky
RisingWorm.Hokobot!8.5646 (TFE:5:i9dIBmv1gCO)
Ad-AwareGen:Variant.Zusy.135070
SophosTroj/Explos-A
ComodoMalware@#138ws24wu57ty
F-SecureTrojan.TR/Agent.357315
DrWebTrojan.Siggen6.37294
ZillyaDropper.Dycler.Win32.783
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
EmsisoftGen:Variant.Zusy.135070 (B)
IkarusTrojan.Win32.Hokobot
GDataGen:Variant.Zusy.135070
JiangminTrojanDropper.Dycler.ib
WebrootW32.Trojan.Gen
AviraTR/Agent.357315
Antiy-AVLTrojan[Dropper]/Win32.Dycler
MicrosoftWorm:Win32/Hokobot.A!dha
Endgamemalicious (high confidence)
ArcabitTrojan.Zusy.D20F9E
ZoneAlarmTrojan-Dropper.Win32.Dycler.vhp
AhnLab-V3Trojan/Win32.Agent.C779663
Acronissuspicious
VBA32BScope.Trojan.KillFiles
ALYacGen:Variant.Zusy.135070
MAXmalware (ai score=100)
ESET-NOD32a variant of Win32/Agent.UAG
TrendMicro-HouseCallBKDR_EXPLOSIVE.A
YandexTrojan.DR.Dycler!gGoR+a3Jq14
SentinelOneDFI – Malicious PE
eGambitTrojan.Generic
FortinetW32/Agent.PTM!tr
Qihoo-360Win32/Trojan.Dropper.53c
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Zusy.135070 (B)?

Zusy.135070 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment