Malware

Zusy.320442 (B) information

Malware Removal

The Zusy.320442 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.320442 (B) virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Zusy.320442 (B)?


File Info:

crc32: 871ACFAF
md5: c780bce7700da221c848758467639716
name: C780BCE7700DA221C848758467639716.mlw
sha1: 35445c49d0be2ff66db4cf65ed8cfa4f1df1a343
sha256: a72f5855431b19a7a9d8346b927017a5a2d7a57a2aefd94a4b3aae2998c7affa
sha512: f29754f44253c35d8a95f836b9cbdc17799fe685bf315164431fdddb553145201f7fb8a82d95332b8f8dc8c4a944111a715e9e0da3167ad9d9e2c0cc0227403d
ssdeep: 6144:78IeYJH/zpzw9B3j/omgK/xuCadyRYOx5y6y:79e2LW9dQmgKwTdkY0y
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2013 Nero AG and its licensors
InternalName: NeroDisc
FileVersion: 15,0,25,0
CompanyName: Nero AG
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: NeroDiscMergeWrongDisc
SpecialBuild: 15,0,25,0
ProductVersion: 15,0,25,0
FileDescription: NeroDiscMergeWrongDisc Application
OriginalFilename: NeroDiscMergeWrongDisc.exe
Translation: 0x0409 0x04e4

Zusy.320442 (B) also known as:

K7AntiVirusTrojan ( 0051e0631 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.Encoder.23514
CynetMalicious (score: 99)
CAT-QuickHealDownldr.Freepds.MUE.ZZ5
ALYacGen:Variant.Zusy.320442
CylanceUnsafe
ZillyaTrojan.CryptXXX.Win32.772
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/CryptXXX.56717d6b
K7GWTrojan ( 0051e0631 )
Cybereasonmalicious.7700da
CyrenW32/S-8ecc9d92!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.DPXE
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.CryptXXX.asdgqk
BitDefenderGen:Variant.Zusy.320442
NANO-AntivirusTrojan.Win32.CryptXXX.evsvda
MicroWorld-eScanGen:Variant.Zusy.320442
TencentWin32.Trojan.Cryptxxx.Szbc
Ad-AwareGen:Variant.Zusy.320442
SophosMal/Generic-S
ComodoMalware@#2hkkb1t7j863j
BitDefenderThetaGen:NN.ZexaF.34170.vy0@amjrx9Ci
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_Crypmic-1
McAfee-GW-EditionBehavesLike.Win32.Generic.fm
FireEyeGeneric.mg.c780bce7700da221
EmsisoftGen:Variant.Zusy.320442 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1110705
Antiy-AVLTrojan/Generic.ASMalwS.22F69C2
MicrosoftRansom:Win32/Tovicrypt.A
GDataGen:Variant.Zusy.320442
Acronissuspicious
McAfeeRansomware-GJA!C780BCE7700D
MAXmalware (ai score=97)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesMalware.AI.2451378745
PandaTrj/Genetic.gen
TrendMicro-HouseCallMal_Crypmic-1
RisingTrojan.Generic@ML.100 (RDML:W7RpKV0bKdGcFgUSbEqi+w)
YandexTrojan.CryptXXX!rMpkZBdb76k
IkarusTrojan-Ransom.Locky
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Zusy.320442 (B)?

Zusy.320442 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment