Categories: Malware

Should I remove “Zusy.365787 (B)”?

The Zusy.365787 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.365787 (B) virus can do?

  • Reads data out of its own binary image
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.365787 (B)?


File Info:

crc32: FFF6823Amd5: 3c35e0772da588042587c659aead2800name: 3C35E0772DA588042587C659AEAD2800.mlwsha1: 7e459cf53004634575dc401d0a395d6173125e67sha256: 100c7e7a25d12d8265daa91654785a941849ac87c19128e920846b9456ceea96sha512: 04f3302a3e65bfb95f100b356a516748639a6567bb02c99b69d2c325e8999135f472118f6125a20eda6dd4ba120c326f995fd28780ac42175e140a15d6b0ffeessdeep: 12288:60sCqLv3ZAeGzdrlviXAmk0V0GuKRef8TAwsg/qN+k/jHqruE6mXj7RO:wfZazhJiXAmk0VDuKRef8UBZN+kjqhjtype: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.365787 (B) also known as:

Elastic malicious (high confidence)
Cynet Malicious (score: 100)
ALYac Gen:Variant.Zusy.365787
Sangfor Trojan.Win32.Save.a
CrowdStrike win/malicious_confidence_90% (W)
Cybereason malicious.72da58
Symantec ML.Attribute.HighConfidence
APEX Malicious
Avast Win32:Malware-gen
ClamAV Win.Ransomware.Avaddon-9852658-0
Kaspersky HEUR:Trojan-Ransom.Win32.Gen.gen
BitDefender Gen:Variant.Zusy.365787
MicroWorld-eScan Gen:Variant.Zusy.365787
Tencent Malware.Win32.Gencirc.11bb9ac3
Ad-Aware Gen:Variant.Zusy.365787
Sophos ML/PE-A
BitDefenderTheta Gen:NN.ZexaF.34688.LuW@a0sIxWoi
VIPRE Trojan.Win32.Generic!BT
TrendMicro Ransom_Gen.R03BC0PEC21
McAfee-GW-Edition BehavesLike.Win32.Injector.jh
FireEye Generic.mg.3c35e0772da58804
Emsisoft Gen:Variant.Zusy.365787 (B)
SentinelOne Static AI – Suspicious PE
Jiangmin Trojan.Gen.bfd
Avira HEUR/AGEN.1141790
eGambit Unsafe.AI_Score_99%
Antiy-AVL Trojan/Generic.ASMalwS.323B255
Microsoft Trojan:Win32/Caynamer.A!ml
GData Gen:Variant.Zusy.365787
AhnLab-V3 Malware/Gen.Reputation.C4313895
McAfee GenericRXNU-BI!3C35E0772DA5
MAX malware (ai score=82)
Malwarebytes Malware.AI.2871092802
Panda Trj/GdSda.A
TrendMicro-HouseCall Ransom_Gen.R03BC0PEC21
Rising Ransom.Gen!8.DE83 (C64:YzY0OlPsX2ilC8IG)
Fortinet W32/Gen.BI!tr
AVG Win32:Malware-gen

How to remove Zusy.365787 (B)?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Generic.Dacic.8952383F.A.55758F89 removal tips

The Generic.Dacic.8952383F.A.55758F89 is considered dangerous by lots of security experts. When this infection is active,…

51 mins ago

Win32/Agent.AGEV removal guide

The Win32/Agent.AGEV is considered dangerous by lots of security experts. When this infection is active,…

52 mins ago

What is “Trojan.Generic.30064921”?

The Trojan.Generic.30064921 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

How to remove “Adware:Win32/Stapcore”?

The Adware:Win32/Stapcore is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Should I remove “Malware.AI.4293759626”?

The Malware.AI.4293759626 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago

Zusy.545749 malicious file

The Zusy.545749 is considered dangerous by lots of security experts. When this infection is active,…

2 hours ago