Malware

Zusy.368564 malicious file

Malware Removal

The Zusy.368564 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.368564 virus can do?

  • Executable code extraction
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • The sample wrote data to the system hosts file.
  • Anomalous binary characteristics

How to determine Zusy.368564?


File Info:

crc32: 23AE99D7
md5: b7f33b5f3cbd3acf981bac49f79ffd03
name: B7F33B5F3CBD3ACF981BAC49F79FFD03.mlw
sha1: 584fb5fa26aa9b277974c634f67be83e9f2857e4
sha256: b61af3f4cadca6f85f0b27f7c5b9de2c2d028ccf76744244011f75312157e296
sha512: ed308bd1bdb1f3e8738f7b6a88c28312f0dc8017c60480e8ca52f0aecbca1589b03ba713b4d045e21b0665666f0a30dcc888b2f9a20cb7f88fa90137464b0bbd
ssdeep: 12288:fKGfIly3PWWZj15Cm57s40AmCb9I0WaxPirAutZzrUDj74iKIfrA5WEJ7U/T3FE4:fKGfGy3Bj1dD0URYLzrU/74ibGpU/T19
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Zusy.368564 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusAdware ( 004b897e1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.368564
CylanceUnsafe
BitDefenderGen:Variant.Zusy.368564
K7GWAdware ( 004b897e1 )
Cybereasonmalicious.f3cbd3
CyrenW32/Heuristic-162!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.FlyStudio potentially unwanted
APEXMalicious
TotalDefenseWin32/EasyDollar_i
NANO-AntivirusVirus.Win32.Agent.dvixmz
MicroWorld-eScanGen:Variant.Zusy.368564
Ad-AwareGen:Variant.Zusy.368564
SophosMal/Zbot-DY
F-SecureHeuristic.HEUR/AGEN.1114785
BitDefenderThetaGen:NN.ZexaCO.34608.MmJfauVJz8bb
VIPRETrojan.Win32.Autorun.dm (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.b7f33b5f3cbd3acf
EmsisoftApplication.Generic (A)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1114785
eGambitUnsafe.AI_Score_95%
MicrosoftProgram:Win32/Wacapew.C!ml
GridinsoftTrojan.Win32.Gen.bot!i
GDataGen:Variant.Zusy.368564
McAfeeFlyagent.d
MAXmalware (ai score=81)
MalwarebytesMalware.Heuristic.1003
RisingMalware.Heuristic!ET#92% (RDMK:cmRtazoEuRldxHs4kcVuamEQ/tUc)
IkarusTrojan.Win32.FlyAgent
FortinetW32/Injector.BELF!tr

How to remove Zusy.368564?

Zusy.368564 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment