Malware

Zusy.372267 information

Malware Removal

The Zusy.372267 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.372267 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

Related domains:

cleosetapi.com

How to determine Zusy.372267?


File Info:

name: CB390D6B2D62B4BF23AA.mlw
path: /opt/CAPEv2/storage/binaries/2e97b95e4450165c14e7dfb386cca4f63991aaf48978af0f7d3b34b706544883
crc32: 9DC29DD0
md5: cb390d6b2d62b4bf23aa5a283d12b6f4
sha1: 5fa0da2ad093fc0fb1f0fde48dd021671358c2a1
sha256: 2e97b95e4450165c14e7dfb386cca4f63991aaf48978af0f7d3b34b706544883
sha512: 4a402b19fbc1f39a5dfd32eecceceb14abee8cb6806b5ff2b376f6b6b606b6f9f387de56c409c53e5c96b32c3906abb5b3db67e838d519d7a476b5c378decaf2
ssdeep: 49152:ZSC5pbo4ZHDe5UJkYXDsEHUFG6KNEo+t3VN8lpMYqjqCAEGlN:Zjpbo4ZHDlhXN0fKNEoeyTlCZ+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T111C50210D7D2602BE8E255FFD0B7A6FD5A607F41A73099CF06C83AD2A32D7859D22907
sha3_384: ea8e50566424ac827bc5d950d3ad5820db00a664426cd25602e5e5d9db3e2a604a3c09cf93ff6f97fb9acb82cff87a80
ep_bytes: 558bec6aff6858e86400680810400064
timestamp: 2021-03-18 13:50:24

Version Info:

FileDescription: BestCrypt Archive Application
FileVersion: 2.07.2
InternalName: BCArchive
LegalCopyright: Copyright © 2004-2020
OriginalFilename: BCArchive.exe
ProductName: BCArchive Application
ProductVersion: 2.07.2
Translation: 0x0409 0x04b0

Zusy.372267 also known as:

LionicHacktool.Win32.ArchSMS.kZuA
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.372267
CAT-QuickHealTrojan.EkstakIH.S19398615
McAfeeGenericRXAA-FA!CB390D6B2D62
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.2970875
SangforTrojan.Win32.Wacatac.B
K7AntiVirusTrojan ( 00588a861 )
AlibabaTrojan:Win32/Ekstak.2cc48de8
K7GWTrojan ( 00588a861 )
Cybereasonmalicious.b2d62b
CyrenW32/Ekstak.AN.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HJZJ
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Ekstak.gen
BitDefenderGen:Variant.Zusy.372267
NANO-AntivirusTrojan.Win32.Ekstak.isyofl
AvastWin32:AdwareX-gen [Adw]
TencentWin32.Trojan.Ekstak.Syrp
Ad-AwareGen:Variant.Zusy.372267
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.Agent.ieuca
DrWebTrojan.DownLoader37.59321
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
FireEyeGeneric.mg.cb390d6b2d62b4bf
EmsisoftGen:Variant.Zusy.372267 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.372267
JiangminTrojan.Ekstak.bppb
AviraTR/Crypt.Agent.ieuca
Antiy-AVLTrojan/Win32.Ekstak
ArcabitTrojan.Zusy.D5AE2B
MicrosoftTrojan:Win32/Tiggre!rfn
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Agent.R372880
VBA32BScope.Trojan.Ekstak
ALYacGen:Variant.Zusy.372267
MAXmalware (ai score=86)
MalwarebytesAdware.DownloadAssistant
YandexTrojan.Ekstak!+YHG305MQSs
IkarusTrojan.Swizzor
FortinetW32/Kryptik.HBNX!tr
BitDefenderThetaGen:NN.ZexaF.34294.zA0@a84@CRdi
AVGWin32:AdwareX-gen [Adw]
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.121218.susgen

How to remove Zusy.372267?

Zusy.372267 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment