Malware

What is “Zusy.367824”?

Malware Removal

The Zusy.367824 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.367824 virus can do?

  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • A process was set to shut the system down when terminated
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.367824?


File Info:

crc32: 312FDD33
md5: 4eb0ee32365ad89815f7d301828c3961
name: 4EB0EE32365AD89815F7D301828C3961.mlw
sha1: d1c0e4e6ac79fbc5d1404702978c412e504b95a3
sha256: acb1f4ef550fac33196296853b54b57cdc39af854bc017dcf88ac8369c6264ba
sha512: 874917d759cec1709c8a00c37612398b74f89f8727005937ed4e67a17fb098e5ebde8ddc40cbe53565748d8a224c5a50f5fc97cd96e7c50a13ab3ec7c418005b
ssdeep: 3072:MEkJY4RpJ4Jj+glM9u9g49MuWVTXcxS5aBDJFUjMs91keEsSDB5xCM0hYSZo51I:MJPQbA2Uc85EQ1keOVSZ4/+KZ9O
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Zusy.367824 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen8.23112
CynetMalicious (score: 100)
CAT-QuickHealRansom.MazeIH.S12850715
ALYacGen:Variant.Zusy.367824
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
Cybereasonmalicious.2365ad
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/KillMBR.NDS
APEXMalicious
AvastMBR:CoViper-A [Trj]
ClamAVWin.Dropper.Tiggre-7061386-1
KasperskyHEUR:Trojan.Win32.KillMBR.gen
BitDefenderGen:Variant.Zusy.367824
NANO-AntivirusTrojan.Win32.DiskWriter.fjkdpb
MicroWorld-eScanGen:Variant.Zusy.367824
TencentMalware.Win32.Gencirc.10ce3cd4
Ad-AwareGen:Variant.Zusy.367824
BitDefenderThetaGen:NN.ZelphiF.34688.nGW@aqnv9Ik
FireEyeGeneric.mg.4eb0ee32365ad898
EmsisoftGen:Variant.Zusy.367824 (B)
JiangminTrojan.DiskWriter.jo
WebrootW32.Trojan.Gen
AviraDR/Delphi.Gen
MicrosoftTrojan:Win32/KillMBR.G!MTB
ZoneAlarmHEUR:Trojan.Win32.KillMBR.gen
GDataGen:Variant.Zusy.367824
AhnLab-V3Malware/Gen.Generic.C2882301
MAXmalware (ai score=88)
VBA32BScope.Trojan.DiskWriter
MalwarebytesTrojan.KillMBR
PandaTrj/GdSda.A
RisingMalware.Heuristic!ET#98% (RDMK:cmRtazpa+a/r8buVvLe+Ghu8o65T)
YandexTrojan.GenAsa!lX/idzb9k7U
IkarusTrojan.Win32.KillMBR
FortinetW32/KillMBR.NDS!tr
AVGMBR:CoViper-A [Trj]

How to remove Zusy.367824?

Zusy.367824 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment