Malware

Should I remove “Zusy.369618”?

Malware Removal

The Zusy.369618 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.369618 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

How to determine Zusy.369618?


File Info:

crc32: 7BCF8B8F
md5: a8cd16553c04919d5c58ef54201699c8
name: A8CD16553C04919D5C58EF54201699C8.mlw
sha1: 3008424a509cd2f829a5ab650fd34822bb5d294b
sha256: 8f31bf58e902ff0f5240f34f3aac3b60ba72661d768c35eec3686487e50980fe
sha512: f469d88197b5e73cf38536d51fa3cb4b1a5190751632115a932ea23d7648b8850a9d4971a2d09448f00a06fa7cfdd5edb9b953291b1ce9df2648683679f4c4fb
ssdeep: 98304:K/9rr4dX5ivZGanT0lYKRH9v9iGge2dnqnu9COH:KRrmtKSHvixdnqnu9LH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright LimerBoy xa9 2020
Assembly Version: 1.0.0.0
InternalName: Clipper.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Google updater
ProductVersion: 1.0.0.0
FileDescription: Google
OriginalFilename: Clipper.exe

Zusy.369618 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0056043f1 )
DrWebTrojan.DownLoader37.64952
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.369618
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanBanker:MSIL/ClipBanker.d7c28634
K7GWTrojan ( 0056043f1 )
Cybereasonmalicious.53c049
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Themida.HSC
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Banker.MSIL.ClipBanker.io
BitDefenderGen:Variant.Zusy.369618
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Variant.Zusy.369618
Ad-AwareGen:Variant.Zusy.369618
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34628.DF2@ayOux7ei
McAfee-GW-EditionArtemis!PUP
FireEyeGeneric.mg.a8cd16553c04919d
EmsisoftGen:Variant.Zusy.369618 (B)
JiangminTrojanDownloader.MSIL.ztb
AviraTR/Crypt.XPACK.Gen
eGambitPE.Heur.InvalidSig
MicrosoftHackTool:Win32/AutoKMS!ml
GridinsoftTrojan.Win32.Agent.sd!n
GDataGen:Variant.Zusy.369618
AhnLab-V3Malware/Gen.RL_Reputation.R366826
McAfeeArtemis!A8CD16553C04
MAXmalware (ai score=85)
VBA32BScope.TrojanPSW.Agent
MalwarebytesTrojan.Clipper
TrendMicro-HouseCallTROJ_GEN.R002H09CK21
RisingMalware.Heuristic!ET#84% (RDMK:cmRtazpDCXOsFM5inbHLzy8HI93X)
YandexTrojan.TPM!h27aFNnrhko
FortinetW32/PossibleThreat
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.ClipBanker.HxMBBB8B

How to remove Zusy.369618?

Zusy.369618 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment