Malware

Zusy.382163 (B) removal guide

Malware Removal

The Zusy.382163 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.382163 (B) virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Queries information on disks, possibly for anti-virtualization
  • Behavior consistent with a dropper attempting to download the next stage.
  • Detects the presence of Wine emulator via registry key
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
ec2-52-29-33-28.eu-central-1.compute.amazonaws.com

How to determine Zusy.382163 (B)?


File Info:

crc32: E2E4E6DE
md5: 2fe2629d753467894d5cef87c038b6a7
name: 2FE2629D753467894D5CEF87C038B6A7.mlw
sha1: 1b4287d9e95d7b3f912dfaae8c66fbebd4e64787
sha256: 5edb2e6e39df7b9df1ab4c5968d799b38c9d99392d1abd98b575a13e5e821e79
sha512: 59ecbc6d165f22c1404a62e3a0fa800a50191018be5ac59ee2c6c5267df821b4e34b4a62a92e272598c16007b8ec77ee0726675f50244440e64f5d425a3390ef
ssdeep: 49152:vvBGEXlJiS6K6cXPGct4YXTe5VhKFjA2+KC+lRS:8WvsJEPGctI5wjA2+KjfS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2005-2017 Piriform Ltd
InternalName: sd.exe
FileVersion: 6.33.0.6130
CompanyName: SudoSoft
ProductName: CCleaner
ProductVersion: 6.33.0.6130
FileDescription: CCleaner
OriginalFilename: sd.exe
Translation: 0x0409 0x04b0

Zusy.382163 (B) also known as:

K7AntiVirusTrojan ( 005231c11 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.2632
CynetMalicious (score: 100)
CAT-QuickHealSwBundler.ICLoader.YB5
ALYacGen:Variant.Zusy.382163
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1343888
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Katusha.65848e23
K7GWTrojan ( 005231c11 )
Cybereasonmalicious.d75346
CyrenW32/S-6cf4b1ed!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GBIH
APEXMalicious
AvastWin32:DangerousSig [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.382163
NANO-AntivirusTrojan.Win32.InstallCube.ewsyqb
MicroWorld-eScanGen:Variant.Zusy.382163
Ad-AwareGen:Variant.Zusy.382163
SophosMal/Generic-S
ComodoTrojWare.Win32.Crypt.B@7o6bny
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXEO-DM!2FE2629D7534
FireEyeGeneric.mg.2fe2629d75346789
EmsisoftGen:Variant.Zusy.382163 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.23E937E
MicrosoftPUADlManager:Win32/InstallCube
GDataGen:Variant.Zusy.382163
AhnLab-V3PUP/Win32.ICLoader.R217745
Acronissuspicious
McAfeeGenericRXEO-DM!2FE2629D7534
MAXmalware (ai score=94)
VBA32BScope.Trojan.Ekstak
MalwarebytesAdware.FileTour
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AFA6 (CLASSIC)
YandexTrojan.GenAsa!Je9diD4rCqY
IkarusPUA.FileTour
MaxSecureAdware.WIN32.AdWare.Generic_212245
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:DangerousSig [Trj]
Paloaltogeneric.ml

How to remove Zusy.382163 (B)?

Zusy.382163 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment