Malware

How to remove “Zusy.382163”?

Malware Removal

The Zusy.382163 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.382163 virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Queries information on disks, possibly for anti-virtualization
  • Detects the presence of Wine emulator via registry key
  • Attempts to modify proxy settings

Related domains:

ec2-52-29-33-28.eu-central-1.compute.amazonaws.com

How to determine Zusy.382163?


File Info:

crc32: 704D2218
md5: bc35dba487442ed4ea9fb1293ec412c0
name: BC35DBA487442ED4EA9FB1293EC412C0.mlw
sha1: 697f6923634c0c444942472663bd8f260196ba1a
sha256: 097a359cd7c7103467144a00424c8a284e6b401b6ed26ce4441e03c1cf5cb74b
sha512: 09e01e28106497513e34ca7590897d743bc6c63d77731007d6024a537256d22134ce5a3181c11fa7c908b7064632907063bd638fcb715dff3065ebe5643930cf
ssdeep: 49152:r9LIcZPZvjzVk6cXPGct4YXTe5VhKFjA2+KC+lR1:5LVZPZ1EPGctI5wjA2+Kjf1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2005-2017 Piriform Ltd
InternalName: sd.exe
FileVersion: 6.33.0.6130
CompanyName: SudoSoft
ProductName: CCleaner
ProductVersion: 6.33.0.6130
FileDescription: CCleaner
OriginalFilename: sd.exe
Translation: 0x0409 0x04b0

Zusy.382163 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0052331a1 )
Elasticmalicious (high confidence)
DrWebTrojan.InstallCube.2551
CAT-QuickHealSwBundler.ICLoader.YB5
McAfeeGenericRXEO-DM!BC35DBA48744
CylanceUnsafe
ZillyaAdware.Generic.Win32.27601
SangforSuspicious.Win32.Save.a
AlibabaAdWare:Win32/Katusha.b14277d3
K7GWTrojan ( 0052331a1 )
Cybereasonmalicious.487442
CyrenW32/S-6f9cd638!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GBGD
APEXMalicious
AvastWin32:AdwareSig [Adw]
CynetMalicious (score: 100)
KasperskyUDS:Packed.Win32.Katusha.gen
BitDefenderGen:Variant.Zusy.382163
NANO-AntivirusTrojan.Win32.InstallCube.ewsbho
MicroWorld-eScanGen:Variant.Zusy.382163
Ad-AwareGen:Variant.Zusy.382163
SophosMal/Generic-S
ComodoTrojWare.Win32.Crypt.B@7o6bny
F-SecureTrojan.TR/Crypt.XPACK.Gen
McAfee-GW-EditionGenericRXEO-DM!BC35DBA48744
FireEyeGeneric.mg.bc35dba487442ed4
EmsisoftApplication.FileTour (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Ekstak.bpzm
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.23DDE91
MicrosoftPUADlManager:Win32/InstallCube
ArcabitTrojan.Zusy.D5D4D3
GDataWin32.Packed.Kryptik.KW
AhnLab-V3PUP/Win32.ICLoader.R217419
Acronissuspicious
VBA32BScope.Trojan.Ekstak
MAXmalware (ai score=98)
MalwarebytesAdware.MegaDowl
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.AFA6 (CLASSIC)
YandexTrojan.GenAsa!7uq5sxGpQTs
IkarusTrojan-Downloader.Agent
MaxSecurePacked.Packed.WIN32.Katusha.gen_212008
FortinetW32/CoinMiner.GYQC!tr
AVGWin32:AdwareSig [Adw]
Paloaltogeneric.ml

How to remove Zusy.382163?

Zusy.382163 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment