Malware

Zusy.333403 (B) removal

Malware Removal

The Zusy.333403 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.333403 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.333403 (B)?


File Info:

crc32: 4CED4223
md5: 68faaf581e68fab4d6dd42ba3f0d18b2
name: 68FAAF581E68FAB4D6DD42BA3F0D18B2.mlw
sha1: d64c2f669e0b3f22cf93665f2d4580518cf06bb3
sha256: b0494082ec5fe1a726f4b73ddb5a35d2d93a8953eb9a530f522d995d9d27ea22
sha512: 9069b44511e8b1c732750b6079d41665e1f216c420d1761e888c5a1a69e4fb043d8c44dccd345126dcb73834401ebb6c2b7affb8eb635e79a3e133ec6b25f0a9
ssdeep: 12288:lSs0bCOuxtlMHHaQPOumOyiAIiZZ5dfQgHo/SNy02hgK6i:qZuxtlMnaNVRiAIiZZgOo/pg9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2005
InternalName: MDI_Notepad
FileVersion: 1, 0, 0, 1
CompanyName:
LegalTrademarks:
ProductName: MDI_Notepad Application
ProductVersion: 1, 0, 0, 1
FileDescription: MDI_Notepad MFC Application
OriginalFilename: MDI_Notepad.EXE
Translation: 0x0409 0x04b0

Zusy.333403 (B) also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.333403
FireEyeGeneric.mg.68faaf581e68fab4
ALYacGen:Variant.Zusy.333403
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderGen:Variant.Zusy.333403
CyrenW32/Emotet.AWS.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Dropper.Emotet-9789045-0
KasperskyHEUR:Trojan-Banker.Win32.Emotet.pef
RisingTrojan.Kryptik!8.8 (TFE:4:qZ3VSDJTkkM)
Ad-AwareGen:Variant.Zusy.333403
EmsisoftGen:Variant.Zusy.333403 (B)
DrWebTrojan.DownLoader35.13759
InvinceaTroj/Emotet-CTC
McAfee-GW-EditionBehavesLike.Win32.Emotet.hh
SophosTroj/Emotet-CTC
IkarusTrojan-Banker.Emotet
WebrootW32.Trojan.Gen
MicrosoftTrojan:Win32/Emotetcrypt.VM!MTB
ArcabitTrojan.Zusy.D5165B
ZoneAlarmHEUR:Trojan-Banker.Win32.Emotet.pef
GDataGen:Variant.Zusy.333403
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Emotet.C4221023
McAfeeEmotet-FSJ!68FAAF581E68
MAXmalware (ai score=83)
VBA32BScope.TrojanBanker.Emotet
MalwarebytesTrojan.MalPack.TRE
ESET-NOD32a variant of Win32/Kryptik.HHJZ
FortinetW32/Kryptik.HEOE!tr
BitDefenderThetaGen:NN.ZexaF.34634.Iu0@aWkRCMii
AVGWin32:BankerX-gen [Trj]

How to remove Zusy.333403 (B)?

Zusy.333403 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment