Malware

Zusy.368127 removal instruction

Malware Removal

The Zusy.368127 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.368127 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine Zusy.368127?


File Info:

name: A921A0BB615BDA3D000D.mlw
path: /opt/CAPEv2/storage/binaries/cc2a46d1c3ebf2cb3c2140a38d73a3caa97c4db4834bf65045473eb810322487
crc32: 62DFE7BA
md5: a921a0bb615bda3d000da77f23136b56
sha1: a4a18298d40c769aaa5f9e3a22d73ff9f74eb959
sha256: cc2a46d1c3ebf2cb3c2140a38d73a3caa97c4db4834bf65045473eb810322487
sha512: 769027a752d53fb247642390f4a1465fe9bba9a480f79c8d37d33fa8b7d1eb464df4532ffdbd44309cec5b27ce58fae3465f3660b2b916f652af6852f8fd9733
ssdeep: 1536:/9T+59U2pmZuL3iedvs4h41v0/wb69YDd1Nyk8yyygZmgTsWEVpcdvprWmVeKJ:/9Tl2pmZi3iem4Lwb69YDdCk5gPm4v9l
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T117735A03B5C2D471E876193658A4E9B19A6FF9201F71DD6B37890A3E0F306D08D39E6B
sha3_384: be1bd5091ca63eaa97dc5561bc5e7948f119422197bc4f3ed6ba0478d3d39da22221e236bb9139e2bf5d5c329fa7bdc7
ep_bytes: e8a3020000e97afeffff558bec8b4508
timestamp: 2022-01-17 18:55:29

Version Info:

0: [No Data]

Zusy.368127 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.ClipBanker.7!c
MicroWorld-eScanGen:Variant.Zusy.368127
FireEyeGeneric.mg.a921a0bb615bda3d
McAfeeRDN/PWS-Banker
CylanceUnsafe
SangforInfostealer.Win32.ClipBanker.gen
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0058dd411 )
K7AntiVirusTrojan ( 0058dd411 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/ClipBanker.OD
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyUDS:Trojan-Banker.Win32.ClipBanker.gen
BitDefenderGen:Variant.Zusy.368127
AvastWin32:Malware-gen
SophosMal/Generic-S
ZillyaTrojan.ClipBanker.Win32.12607
TrendMicroTROJ_GEN.R011C0PAL22
McAfee-GW-EditionRDN/PWS-Banker
EmsisoftGen:Variant.Zusy.368127 (B)
eGambitUnsafe.AI_Score_99%
AviraTR/Spy.ClipBanker.cyutr
MAXmalware (ai score=85)
Antiy-AVLTrojan[Banker]/Win32.ClipBanker
GridinsoftRansom.Win32.Banker.sa
MicrosoftTrojan:Win32/Tnega!ml
ViRobotTrojan.Win32.Z.Clipbanker.78848.A
ZoneAlarmUDS:Trojan-Banker.Win32.ClipBanker.gen
GDataGen:Variant.Zusy.368127
AhnLab-V3Trojan/Win.PWS-Banker.C4955032
ALYacGen:Variant.Zusy.368127
VBA32TrojanBanker.ClipBanker
TrendMicro-HouseCallTROJ_GEN.R011C0PAL22
RisingTrojan.ClipBanker!8.5FB (CLOUD)
IkarusTrojan.Spy.ClipBanker
MaxSecureTrojan.Malware.73484953.susgen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
Cybereasonmalicious.b615bd

How to remove Zusy.368127?

Zusy.368127 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment