Malware

Zusy.378574 (B) removal instruction

Malware Removal

The Zusy.378574 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.378574 (B) virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.

How to determine Zusy.378574 (B)?


File Info:

crc32: 267ADD21
md5: b6acea7e2c4f8985f2f5279bc7009590
name: B6ACEA7E2C4F8985F2F5279BC7009590.mlw
sha1: e1523812b8af8cc39cdf765f7e38a7f31b8f8773
sha256: a2c365699b9ab9300bd6d3c4dcd148e23c2243dd497e9bcaf44900c7841d4805
sha512: ba5d206d32887f0ac6c58d47371e8f33e746d6e89ee448cf6c51afb79a531c2d19f26bb0af4583ab1dbd667cbdd378067674e81b4f3430e41cddaa725142179a
ssdeep: 24576:toJBu2XV04jnHW8VwBYcdCa3sM6zlYzLhQ0zJ68VQWWRWqM:6u4jHmScdCcsvWkq3
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1997-2020 Simon Tatham.
InternalName: PuTTY
FileVersion: Release 0.74 (with embedded help)
CompanyName: Simon Tatham
ProductName: PuTTY suite
ProductVersion: Release 0.74
FileDescription: SSH, Telnet and Rlogin client
OriginalFilename: PuTTY
Translation: 0x0809 0x04b0

Zusy.378574 (B) also known as:

K7AntiVirusTrojan ( 005325ae1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.378574
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Swrort.b0ac5325
K7GWTrojan ( 005325ae1 )
Cybereasonmalicious.e2c4f8
CyrenW32/Shellter.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Rozena.AMX.gen
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.Win32.Cometer.gen
BitDefenderGen:Variant.Zusy.378574
MicroWorld-eScanGen:Variant.Zusy.378574
Ad-AwareGen:Variant.Zusy.378574
SophosML/PE-A + ATK/Shellter-C
BitDefenderThetaGen:NN.ZexaF.34738.cD0@aqjznfii
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R005C0DFC21
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.b6acea7e2c4f8985
EmsisoftGen:Variant.Zusy.378574 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1125217
MicrosoftTrojan:Win32/Swrort.A
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Zusy.378574
AhnLab-V3Malware/Win32.RL_Generic.R358066
McAfeeMalHeur-FAG!B6ACEA7E2C4F
MAXmalware (ai score=82)
VBA32BScope.Trojan.Swrort
MalwarebytesMachineLearning/Anomalous.96%
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R005C0DFC21
RisingTrojan.Generic@ML.100 (RDML:dcRuKvZlIz3sOFdAg+p8mw)
IkarusTrojan.Win32.Rozena
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Shellter.C!tr
AVGFileRepMalware

How to remove Zusy.378574 (B)?

Zusy.378574 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment