Categories: Malware

What is “Zusy.364383”?

The Zusy.364383 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.364383 virus can do?

  • Mimics the system’s user agent string for its own requests
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Deletes its original binary from disk
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

rcoxshllfoldxie.org
kdsdsapurvgf.biz
isnkrauswyvjne.biz
vtwktxlqhluymj.ru
jxxmaphdxrrkea.org
wxrywbxdwbfvmd.co.uk
kcsbdstpnhchny.info
xdcbfqknxtbwtk.com
lhddligaoaxilt.net
dtwnptyqiyhcph.biz
ejxbhlslykuvyu.ru
eyhpxjlbjrddpb.org
foidpbfvadqwpf.co.uk
fdcebmxnyhnaed.info
gsdrseripsbtnj.com
gimgjckxaajblv.net
hxntbtesqlwuls.biz
jomtvripjmxfsv.ru
wsnvcmuybyqyks.org
lwwujhummresjj.co.uk
ybxwpchveewmkp.info
lxrkhkhmauedsb.com
ycsmnftvrhwwkq.net
ngcluatjdakqqh.biz
bkdnbugsumdkrg.ru
rtwyadiolscrsp.org
sjxmrxsddktdsw.co.uk
tchansuloxifjo.info
urinfnfagpaqsi.com
tdcplvhlcbipho.net
usdddqratsabho.biz
vlmqyltifgodfg.ru
wbneqgewwxgoos.org
rmyboxopspjhkf.co.uk
fotfipkcgjpwlb.info
srjdwhttwwnyra.com
gtehqypgkqtojj.net
vceusdybqiqngp.biz
jeyymuunecwdhs.ru
whowbmefupufgr.org
kjjbuearijbuxi.co.uk
vfjqfjkydoowcs.info
wsecjbetqclqly.com
wktsnspdhvsojy.net
xxoerkjxujpijv.biz
auokjoukbhvdjj.ru
bijvngofouswsw.org
baymrxaofoaujw.co.uk
cntxvptjscwojb.info
gmymyhxccekfgb.com
totqscklesyyxq.net
iujnmqdmiticeb.biz
vwerglpvkiwvfa.ru
kcegdminawrlco.org
xeykwhuwclgftl.co.uk
mkohqvnxgmpisp.info
amjlkqahibectv.com
kfjcpstamdxyub.net
lsentneoolmoub.biz
mntddcykssvvsm.ru
nboohwjyubklcy.org
ouovtxelkvffcu.co.uk
pijhxsoametucc.info
qdywhhjvqldcsh.com
rqtilctkstrrcb.net
ompuxvukgindbv.biz
cokyrnqwtctscr.ru
prawglhuhbjebe.org
dtubaddhuuptsn.co.uk
qvuljbdiirmapq.info
exppdsyuvlspqt.com
rbfnrqpsjkibwx.net
fdarlilfweoqoo.biz
sfakohqtqhsssp.ru
tsuvsykoeupmcv.org
tkkmwwderaotsj.co.uk
uxfxbowyfnlnsg.info
uofbamyrsqrpse.com
vcameesmgeojcr.net
vtpdiclctjnqaw.biz
whkomtfwhwkkab.ru
dmpgifetpugmhe.org
qokkcaqdrjugyt.co.uk
fuahvuqqsamaxr.info
swulppdauobtyq.com
fvuwtkmrrefjvc.net
sxpbnfybtstdny.biz
hefxhayoujlwti.ru
ugacbulxwxaquo.org
hfavyqarattgvk.co.uk
isuhdlkgccivvk.info

How to determine Zusy.364383?


File Info:

crc32: 35FC0D94md5: 8bcc561ef4d0ceaed3cdc3ae0c77575aname: 8BCC561EF4D0CEAED3CDC3AE0C77575A.mlwsha1: 1573a112334e5f94b9a580ad1bae5cd872e3a040sha256: 1dec40385522800dfed483b645da71c1ee3afbbdec27e567662972d59c5cbf25sha512: c9c43c1d2689386c465f14a8fe94d2c696964083273655b4876a0ffffbca8f49222c4cc2060d07bcb6a33287a308bb5c067c582f5d452cd5ab121ee3a38fc629ssdeep: 6144:ZyJDysPRciX7JkCpDWgTO3x5N22vWvLRKKAX5l++SyVI4xZ:0Dt6iXdkChT85I2vCMX5l+Zn4type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.364383 also known as:

Bkav W32.AIDetect.malware2
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Zusy.364383
FireEye Generic.mg.8bcc561ef4d0ceae
McAfee Artemis!8BCC561EF4D0
Malwarebytes MachineLearning/Anomalous.100%
VIPRE Trojan.Win32.Cryptolocker.mc (fs)
AegisLab Trojan.Win32.Blocker.j!c
Sangfor Virus_Suspicious.Win32.Sality.ae
K7AntiVirus Trojan ( 0040f66a1 )
BitDefender Gen:Variant.Zusy.364383
K7GW Trojan ( 0040f66a1 )
BitDefenderTheta Gen:NN.ZexaF.34590.xuY@aKwj41bi
Symantec ML.Attribute.HighConfidence
APEX Malicious
Avast Win32:Ransom-AQL [Trj]
Kaspersky Trojan-Ransom.Win32.Blocker.crrj
Alibaba Trojan:Win32/Starter.ali2000005
NANO-Antivirus Trojan.Win32.Blocker.clhzqv
Rising Trojan.CryptoLocker!1.9E7C (CLOUD)
Ad-Aware Gen:Variant.Zusy.364383
Sophos Mal/Ransom-BW
Comodo Malware@#1qhvsyrld3y4r
F-Secure Heuristic.HEUR/AGEN.1123429
DrWeb Trojan.Encoder.329
Zillya Trojan.Blocker.Win32.12057
TrendMicro TROJ_CRILOCK.AS
McAfee-GW-Edition BehavesLike.Win32.Emotet.fc
Emsisoft Gen:Variant.Zusy.364383 (B)
Ikarus Trojan.Win32.Crilock
GData Gen:Variant.Zusy.364383
Webroot W32.Ransom.Blocker
Avira HEUR/AGEN.1123429
Antiy-AVL Trojan[Ransom]/Win32.Blocker
Arcabit Trojan.Zusy.D58F5F
SUPERAntiSpyware Trojan.Agent/Gen-Ransom
ZoneAlarm Trojan-Ransom.Win32.Blocker.crrj
Microsoft Ransom:Win32/Crilock.A
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win32.Cryptolocker.R145793
VBA32 Trojan-Ransom.Blocker
ALYac Gen:Variant.Zusy.364383
MAX malware (ai score=100)
Panda Generic Malware
ESET-NOD32 a variant of Win32/Filecoder.BQ
TrendMicro-HouseCall TROJ_CRILOCK.AS
Tencent Win32.Trojan.Blocker.Eehw
Yandex Trojan.Blocker!BAGhmPQThGE
SentinelOne Static AI – Suspicious PE
eGambit Unsafe.AI_Score_99%
Fortinet W32/Blocker.BW!tr
MaxSecure Trojan.Malware.6624491.susgen
AVG Win32:Ransom-AQL [Trj]
Cybereason malicious.ef4d0c
Paloalto generic.ml
Qihoo-360 Win32/Ransom.Blocker.HxQBy6cA

How to remove Zusy.364383?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry
Tags: amjlkqahibectv.comauokjoukbhvdjj.rubaymrxaofoaujw.co.ukbijvngofouswsw.orgbkdnbugsumdkrg.rucntxvptjscwojb.infocokyrnqwtctscr.rudmpgifetpugmhe.orgdtubaddhuuptsn.co.ukdtwnptyqiyhcph.bizejxbhlslykuvyu.ruexppdsyuvlspqt.comeyhpxjlbjrddpb.orgfdarlilfweoqoo.bizfdcebmxnyhnaed.infofoidpbfvadqwpf.co.ukfotfipkcgjpwlb.infofuahvuqqsamaxr.infofvuwtkmrrefjvc.netgimgjckxaajblv.netgmymyhxccekfgb.comgsdrseripsbtnj.comgtehqypgkqtojj.nethefxhayoujlwti.ruhfavyqarattgvk.co.ukhxntbtesqlwuls.bizisnkrauswyvjne.bizisuhdlkgccivvk.infoiujnmqdmiticeb.bizjeyymuunecwdhs.rujomtvripjmxfsv.rujxxmaphdxrrkea.orgkcegdminawrlco.orgkcsbdstpnhchny.infokdsdsapurvgf.bizkfjcpstamdxyub.netkjjbuearijbuxi.co.uklhddligaoaxilt.netlsentneoolmoub.bizlwwujhummresjj.co.uklxrkhkhmauedsb.commkohqvnxgmpisp.infomntddcykssvvsm.runboohwjyubklcy.orgngcluatjdakqqh.bizompuxvukgindbv.bizouovtxelkvffcu.co.ukpijhxsoametucc.infoprawglhuhbjebe.orgqdywhhjvqldcsh.comqokkcaqdrjugyt.co.ukqvuljbdiirmapq.inforbfnrqpsjkibwx.netrcoxshllfoldxie.orgrmyboxopspjhkf.co.ukrqtilctkstrrcb.netrtwyadiolscrsp.orgsfakohqtqhsssp.rusjxmrxsddktdsw.co.uksrjdwhttwwnyra.comswulppdauobtyq.comsxpbnfybtstdny.biztchansuloxifjo.infotdcplvhlcbipho.nettkkmwwderaotsj.co.uktotqscklesyyxq.nettsuvsykoeupmcv.orgugacbulxwxaquo.orguofbamyrsqrpse.comurinfnfagpaqsi.comusdddqratsabho.bizuxfxbowyfnlnsg.infovcameesmgeojcr.netvceusdybqiqngp.bizvfjqfjkydoowcs.infovlmqyltifgodfg.ruvtpdiclctjnqaw.bizvtwktxlqhluymj.ruvwerglpvkiwvfa.ruwbneqgewwxgoos.orgwhkomtfwhwkkab.ruwhowbmefupufgr.orgwktsnspdhvsojy.netwsecjbetqclqly.comwsnvcmuybyqyks.orgwxrywbxdwbfvmd.co.ukxdcbfqknxtbwtk.comxeykwhuwclgftl.co.ukxxoerkjxujpijv.bizybxwpchveewmkp.infoycsmnftvrhwwkq.netZusy.364383

Recent Posts

MSIL/GenKryptik.GXIZ information

The MSIL/GenKryptik.GXIZ is considered dangerous by lots of security experts. When this infection is active,…

1 month ago

Malware.AI.2789448175 (file analysis)

The Malware.AI.2789448175 is considered dangerous by lots of security experts. When this infection is active,…

1 month ago

Jalapeno.1878 removal instruction

The Jalapeno.1878 is considered dangerous by lots of security experts. When this infection is active,…

1 month ago

What is “Trojan.Heur3.LPT.YmKfaKBcBekib”?

The Trojan.Heur3.LPT.YmKfaKBcBekib is considered dangerous by lots of security experts. When this infection is active,…

1 month ago

How to remove “Worm.Win32.Vobfus.exmt”?

The Worm.Win32.Vobfus.exmt is considered dangerous by lots of security experts. When this infection is active,…

1 month ago

About “TrojanDownloader:Win32/Beebone.JO” infection

The TrojanDownloader:Win32/Beebone.JO is considered dangerous by lots of security experts. When this infection is active,…

1 month ago