Malware

Zusy.158363 (B) information

Malware Removal

The Zusy.158363 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.158363 (B) virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Zusy.158363 (B)?


File Info:

crc32: 52EB847C
md5: 1b3dd90c2b0259f29109003f7bcbaccd
name: 1B3DD90C2B0259F29109003F7BCBACCD.mlw
sha1: c1f0925cb3b6c3e917753d5be1e5e13504e3f12f
sha256: 902d4a6561a5207a8722c1b0ebd2d92f7aba8125bc0523c87c423b96172f9737
sha512: 9fabe640b64a8c81b22216ff414e92c47b26e7ba3caabae5366a935fe620c6bd12e590a076adb2e4080233c5a67b1859666395be334890f9dc4ac534d4eb5c74
ssdeep: 24576:nnNx08HQ5zHbcmPxk/CPhyHEuQ8Gsvv34rIz56AWupltf+LcU78PexWa6:nngB5z7cmPd1uCSwrIwJKvOEeP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.158363 (B) also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 7000000f1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader7.9477
McAfeeGenericR-DTK!1B3DD90C2B02
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.63073
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/DelfInject.ali2000015
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.c2b025
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.ZUN
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Blocker.spp
BitDefenderGen:Variant.Zusy.158363
NANO-AntivirusTrojan.Win32.Blocker.cufngw
ViRobotTrojan.Win32.A.Blocker.1206272
MicroWorld-eScanGen:Variant.Zusy.158363
TencentTrojan-ransom.Win32.Blocker.kjb
Ad-AwareGen:Variant.Zusy.158363
SophosMal/Generic-S
BitDefenderThetaAI:Packer.68042D5919
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.1b3dd90c2b0259f2
EmsisoftGen:Variant.Zusy.158363 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1126519
eGambitUnsafe.AI_Score_95%
MicrosoftTrojan:Win32/Dynamer!ac
GDataGen:Variant.Zusy.158363
AhnLab-V3Trojan/Win32.Blocker.R67151
VBA32TScope.Trojan.Delf
MAXmalware (ai score=82)
MalwarebytesMalware.AI.3963636539
PandaTrj/Genetic.gen
RisingMalware.Undefined!8.C (TFE:dGZlOgSgS+8zmeXwZA)
YandexTrojan.Blocker!KqamN9F0E74
IkarusTrojan.Win32.Agent
FortinetW32/Dropper.XUQ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HwUB3KUA

How to remove Zusy.158363 (B)?

Zusy.158363 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment