Malware

Zusy.333836 removal guide

Malware Removal

The Zusy.333836 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.333836 virus can do?

  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Modifies boot configuration settings
  • Exhibits behavior characteristic of Cerber ransomware
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Zusy.333836?


File Info:

crc32: 75CE01E8
md5: aefeef724797d9fff64e56e190a5cf88
name: AEFEEF724797D9FFF64E56E190A5CF88.mlw
sha1: 61689c0c560a5852dec611bd4f8d13e3482aff59
sha256: 8baecf1f71c0f5ec749e0cea3760d6c6a048076433f99b0a9fb34faa59e7b0f2
sha512: 3dde9f641125533b59293e63ac590d2bcf0c6795c65ec3c4ea7e94dac5b00eab31584c7f57cdb93d877ee0ad55a828e4c06b2e721b0d6c5ddf012a29b0b69164
ssdeep: 3072:Zl8tK/CuVkjnlDnYGywfzWolH/VvSqwy5SvwXhuBJaG9T3pa2Dc8HkJy3i:ZgK/lkjnlNZfN9t6tBwRuKAT3o2gdz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Gowks
InternalName: dutch
FileVersion: 9.8.0.19697
CompanyName: Gowks
ProductName: dutch clits owd
ProductVersion: 9.8.0.19697
FileDescription: dutch overgive
OriginalFilename: dutch.exe
Translation: 0x0409 0x04b0

Zusy.333836 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004f25071 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4794
McAfeeRansomware-GIX!AEFEEF724797
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Zerber.3cda71e2
K7GWTrojan ( 004f25071 )
Cybereasonmalicious.24797d
ESET-NOD32a variant of Win32/Kryptik.FAJB
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Zerber.fhxd
BitDefenderGen:Variant.Zusy.333836
NANO-AntivirusTrojan.Win32.Zerber.evklro
MicroWorld-eScanGen:Variant.Zusy.333836
TencentWin32.Trojan.Zerber.Lsmg
Ad-AwareGen:Variant.Zusy.333836
SophosMal/Generic-R + Mal/Cerber-C
ComodoTrojWare.Win32.Ransom.Cerber.B@6f9bx1
BitDefenderThetaGen:NN.ZexaF.34608.iq1@amu8gfhi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Downloader.ch
FireEyeGeneric.mg.aefeef724797d9ff
EmsisoftGen:Variant.Zusy.333836 (B)
AviraHEUR/AGEN.1123152
MicrosoftRansom:Win32/Cerber.A
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Zusy.333836
VBA32TrojanRansom.Zerber
MAXmalware (ai score=99)
PandaTrj/GdSda.A
RisingRansom.Zerber!8.518C (CLOUD)
YandexTrojan.Zerber!ftaFXkdgrcA
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.EYKI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Cerber.HgIASOoA

How to remove Zusy.333836?

Zusy.333836 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment