Malware

Should I remove “Zusy.170236”?

Malware Removal

The Zusy.170236 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.170236 virus can do?

  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Creates a copy of itself
  • The sample wrote data to the system hosts file.
  • Attempts to modify or disable Security Center warnings

Related domains:

z.whorecord.xyz
a.tomx.xyz
effortbuilt.net
thosewhile.net
journeymeasure.net
creightonaraminta.net
leastform.net
mostaugust.net

How to determine Zusy.170236?


File Info:

crc32: 2362F780
md5: 8506fd84b896572c6f487967ba6bc443
name: 8506FD84B896572C6F487967BA6BC443.mlw
sha1: 5fa846cdeb6ce9c24bcf7d5d32726f6a39cc8d0a
sha256: efb489aa960d45922665cd9e38c68cb68a85bb99dd196bd7db3f6bcc2f68d10d
sha512: 7308bb3d73e4ba197997fd754d981d7823e362a5e3729ac53601876204cd4dfcb83e7d60cc5de86f0c29d6b63eb70ee84992233fc7bbde0c3ede2a5672b1257a
ssdeep: 49152:egc4k9P+1xbq2BgI5kMXE4x7nid2J/70UY7Uqe+3i:egt4P+1xbq2BgI5FXfx7id2J/jo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.170236 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader25.54616
MicroWorld-eScanGen:Variant.Zusy.170236
FireEyeGeneric.mg.8506fd84b896572c
CAT-QuickHealTrojanspy.Nivdort.S4
McAfeeNivdort!8506FD84B896
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Symmi.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004d7cd41 )
BitDefenderGen:Variant.Zusy.170236
K7GWTrojan ( 004d4f0d1 )
Cybereasonmalicious.4b8965
BitDefenderThetaGen:NN.ZexaF.34804.SnW@auDsUwp
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_BAYROB.SM9
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Bayrob.2217df98
NANO-AntivirusTrojan.Win32.Kryptik.euwyvu
RisingTrojan.Generic!8.C3 (CLOUD)
Ad-AwareGen:Variant.Zusy.170236
EmsisoftGen:Variant.Zusy.170236 (B)
ComodoMalware@#2dgyk3lc53wg9
F-SecureHeuristic.HEUR/AGEN.1102747
ZillyaTrojan.Generic.Win32.1292237
TrendMicroTROJ_BAYROB.SM9
McAfee-GW-EditionBehavesLike.Win32.DLAssistant.th
SentinelOneStatic AI – Suspicious PE
SophosML/PE-A + Troj/Nivdor-D
IkarusTrojan.Win32.Crypt
JiangminTrojan.Generic.gpbgn
AviraHEUR/AGEN.1102747
MicrosoftTrojan:Win32/Nivdort.A
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Zusy.D298FC
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Zusy.170236
CynetMalicious (score: 85)
VBA32BScope.Trojan.Nivdort
ALYacGen:Variant.Zusy.170236
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Genetic.gen
APEXMalicious
ESET-NOD32a variant of Win32/Bayrob.CR
TencentWin32.Trojan.Generic.Dxmk
YandexTrojan.Agent!yJG7Y0RTgzw
FortinetW32/Bayrob.AQ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Trojan.09e

How to remove Zusy.170236?

Zusy.170236 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment