Malware

Should I remove “Zusy.362564 (B)”?

Malware Removal

The Zusy.362564 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.362564 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Created a process from a suspicious location
  • Creates a copy of itself

How to determine Zusy.362564 (B)?


File Info:

name: 2A9711F9E8A71838CC70.mlw
path: /opt/CAPEv2/storage/binaries/3ea549328cf2975b1106c12d0e6ae518bf9a4b3fea2029e2f8463ef9a993b517
crc32: 5442A302
md5: 2a9711f9e8a71838cc70e36f72c0d8fe
sha1: 50d5724809874a5cde659e33f56998add6d4ea40
sha256: 3ea549328cf2975b1106c12d0e6ae518bf9a4b3fea2029e2f8463ef9a993b517
sha512: cf5b08a65969ed3d82612ccdbb3e0a7cdb36e2b32adb3e16b0cc84a65d7b5fc85f11406dbe8533b5cbf6855ae69262833af18dad7e1c760548028b72614325ef
ssdeep: 49152:xkXcLfApCsA+DoarLWTkU8YtN/+voG7YetxIf7saw:X4gsA+EanWTVZtB+v+e2
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T19775337503C7AE06F1CB70307E32268D23CA197B4B5AFEAD41C9254AC0AB5DC94F576A
sha3_384: da5fa55f9beee3a96fdbd6b62ea71c375c13e1d6c949404bfe957309d89a09d9caa2fdc49abe039c4176c4df1ae33102
ep_bytes: b8000000005121d7578b3c2483c4045b
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Zusy.362564 (B) also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.362564
FireEyeGen:Variant.Zusy.362564
ALYacGen:Variant.Zusy.362564
MalwarebytesTrojan.Crypt
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderGen:Variant.Zusy.362564
K7GWTrojan ( 0058c5ff1 )
K7AntiVirusTrojan ( 0058c5ff1 )
CyrenW32/CoinMiner.CQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HITO
APEXMalicious
Kasperskynot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
TencentTrojan.Win32.Coinminer.yi
Ad-AwareGen:Variant.Zusy.362564
SophosML/PE-A
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.Packed2.43250
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGen:Variant.Zusy.362564 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ULPM.Gen
Antiy-AVLGrayWare/Win32.Kryptik.ffp
ZoneAlarmnot-a-virus:HEUR:RiskTool.Win32.BitCoinMiner.vho
GDataGen:Variant.Zusy.362564 (2x)
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.CoinMiner.R369357
MAXmalware (ai score=81)
VBA32Trojan.Packed
CylanceUnsafe
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.D238 (RDMK:cmRtazpXRKIiRODjBsK42kOo/bqS)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EAHK!tr
BitDefenderThetaGen:NN.ZexaF.34182.InZ@a8twoXh
AVGWin32:CoinminerX-gen [Trj]
Cybereasonmalicious.9e8a71
AvastWin32:CoinminerX-gen [Trj]

How to remove Zusy.362564 (B)?

Zusy.362564 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment