Malware

About “Zusy.360836 (B)” infection

Malware Removal

The Zusy.360836 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.360836 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Deletes its original binary from disk
  • Attempts to modify proxy settings
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
zipansion.com
hurirk.net
a.tomx.xyz

How to determine Zusy.360836 (B)?


File Info:

crc32: F011CF5C
md5: fa77173e6ba42afa5884084af90ee3ea
name: FA77173E6BA42AFA5884084AF90EE3EA.mlw
sha1: db936e50b73b22710dc438e2cd6b05d5b016d5f3
sha256: 4765932a01c4cdf4d4f169b538d6c4e3eab0d3d241e2eacf8b126f8e32d809bb
sha512: 9ecc1a0b56e6e5f05ee8788873f2cbf5dedfa84b37e17f2fb8cde919faeb54b98f58038d2f6576d2b7c72356166ad25f1b69f91eee28f60a17385a25f2e67ba4
ssdeep: 24576:ROaUEcc1Y7Pj2uqIs+4oumB1Y3ufVmfYL0DvInXEKXW0j1AdZ8xU9/9Us:s7fPmVo57Kfg0DvInXlWkmZrR9j
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

0: [No Data]

Zusy.360836 (B) also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004bcce41 )
LionicTrojan.Win32.Copak.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Packed2.43250
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.360836
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (W)
AlibabaTrojan:Win32/Copak.47d4b229
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.e6ba42
CyrenW32/CoinMiner.CP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.DZQA
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Copak.pef
BitDefenderGen:Variant.Zusy.360836
NANO-AntivirusTrojan.Win32.Copak.izdkcf
MicroWorld-eScanGen:Variant.Zusy.360836
TencentWin32.Trojan.Copak.Eeqx
Ad-AwareGen:Variant.Zusy.360836
SophosMal/HckPk-A
ComodoPacked.Win32.MUPX.Gen@24tbus
BitDefenderThetaGen:NN.ZexaF.34170.unW@aOrsNaf
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.fa77173e6ba42afa
EmsisoftGen:Variant.Zusy.360836 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3474843
MicrosoftTrojan:Win32/Injector.RAQ!MTB
ArcabitTrojan.Zusy.D58184
ZoneAlarmHEUR:Trojan.Win32.Copak.pef
GDataGen:Variant.Zusy.360836
AhnLab-V3Trojan/Win.Generic.R420543
McAfeeGenericRXAA-AA!FA77173E6BA4
MAXmalware (ai score=83)
VBA32BScope.Trojan.Wacatac
MalwarebytesTrojan.Injector.Generic
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0RIJ21
RisingTrojan.Kryptik!1.D12D (CLASSIC)
IkarusTrojan.Win32.Injector
MaxSecureVirus.Sality.AA
FortinetW32/Kryptik.EAHK!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Zusy.360836 (B)?

Zusy.360836 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment