Malware

Zusy.372803 (file analysis)

Malware Removal

The Zusy.372803 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.372803 virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

How to determine Zusy.372803?


File Info:

crc32: AEF9413B
md5: 5f2e7e8d0b0dea5a53310ca14b66310f
name: 5F2E7E8D0B0DEA5A53310CA14B66310F.mlw
sha1: 2fef52387a93e58e5bd4740ba6c3a73910272a29
sha256: 918762466acf2b1623dc7e360c7245252385fad4587c00211cf6a71ad6efb19d
sha512: 426f9aa5144450dc0eff341fc522de053551f3dc0f05a973d2c349e02b719facb3a87dbf5866c7a5b9710ae04e0854f3abea9ae4d63a13defceb5e04d05a2d6d
ssdeep: 3072:k8zQbzy5BPI/n4JJbD+4SFkqvqI9FU2bR:kr2zPn/bq4SFkihvR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: MSRATING
FileVersion: 6.00.2600.0000 (xpclient.010817-1148)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
OleSelfRegister:
ProductVersion: 6.00.2600.0000
FileDescription: Internet Ratings and Local User Management DLL
OriginalFilename: MSRATING.DLL
Translation: 0x0409 0x04b0

Zusy.372803 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusSpyware ( 000287dc1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.946
CynetMalicious (score: 100)
CAT-QuickHealTrojanSpy.Zbot
ALYacGen:Variant.Zusy.372803
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
K7GWSpyware ( 000287dc1 )
Cybereasonmalicious.d0b0de
CyrenW32/Zbot.IT.gen!Eldorado
SymantecW32.Cridex!gen3
ESET-NOD32a variant of Win32/Kryptik.AJGE
APEXMalicious
AvastWin32:Cryptor
KasperskyTrojan-Spy.Win32.Zbot.elqq
BitDefenderGen:Variant.Zusy.372803
NANO-AntivirusTrojan.Win32.Zbot.wmunu
MicroWorld-eScanGen:Variant.Zusy.372803
TencentMalware.Win32.Gencirc.10b40627
Ad-AwareGen:Variant.Zusy.372803
SophosML/PE-A + Mal/EncPk-AHC
ComodoTrojWare.Win32.Spy.Zbot.AJM@4q3hmb
BitDefenderThetaGen:NN.ZexaF.34662.jq1@a8Hpgnoi
VIPRETrojan.Win32.Reveton.a (v)
TrendMicroTSPY_FAREIT.AJY
McAfee-GW-EditionBehavesLike.Win32.ZBot.ch
FireEyeGeneric.mg.5f2e7e8d0b0dea5a
EmsisoftGen:Variant.Zusy.372803 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.chal
AviraTR/Graftor.385561
MicrosoftVirTool:Win32/Obfuscator.ACH
ZoneAlarmTrojan-Spy.Win32.Zbot.elqq
GDataGen:Variant.Zusy.372803
AhnLab-V3Spyware/Win32.Zbot.R53013
Acronissuspicious
McAfeePWS-Zbot.gen.ajj
MAXmalware (ai score=80)
VBA32BScope.Backdoor.Sinowal.5
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_FAREIT.AJY
RisingSpyware.Zbot!8.16B (RDMK:cmRtazqhrK4vq1OMBp8W0f5EFvc9)
IkarusTrojan.Win32.Yakes
FortinetW32/Bublik.AM!tr
AVGWin32:Cryptor
Qihoo-360HEUR/QVM20.1.4548.Malware.Gen

How to remove Zusy.372803?

Zusy.372803 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment