Malware

Zusy.405563 (B) removal tips

Malware Removal

The Zusy.405563 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.405563 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial binary language: Russian
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.405563 (B)?


File Info:

crc32: E8F855BE
md5: 12c205c947c95caad4fe9bc64f237d47
name: 12C205C947C95CAAD4FE9BC64F237D47.mlw
sha1: 822f7ae433fa6535667297856ebf36281683a856
sha256: d4e255bf3ed7df664b7cf75e15bddfaac78808cdd36d976964ce454184000da6
sha512: 2f28f4ae621f5851968dcfbf30dbd4ec2223a6649e78f2eec0b5f42336d52fdbc00eac8d06ac7cf3e79d4a338b512e823f419b1c83be332e49b1301c2b567e59
ssdeep: 12288:VYBTSMFuacpuBPnpqYdUuxuLcpN22kt9+X8LChJWIkCWoCTQnHpxgPh014:yFAKuWN2j28mhkIk32HpxgPh014
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Cat Logic
InternalName: Catalogic Book List
FileVersion: 0.8.0.13
CompanyName: Cat Logic
LegalTrademarks:
Comments:
ProductName: CatList
ProductVersion:
FileDescription: x414x43ex43cx430x448x43dx44fx44f x431x438x431x43bx438x43ex442x435x43ax430
OriginalFilename:
Translation: 0x0419 0x04e3

Zusy.405563 (B) also known as:

K7AntiVirusTrojan ( 005821bc1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.405563
CylanceUnsafe
K7GWTrojan ( 005821bc1 )
Cybereasonmalicious.433fa6
CyrenW32/Kryptik.FPV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HLQM
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Staser.gen
BitDefenderGen:Variant.Zusy.405563
MicroWorld-eScanGen:Variant.Zusy.405563
Ad-AwareGen:Variant.Zusy.405563
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34266.qz0@a8!zIXxO
McAfee-GW-EditionBehavesLike.Win32.Trojan.tc
FireEyeGeneric.mg.12c205c947c95caa
EmsisoftGen:Variant.Zusy.405563 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.Tewgol.dxclh
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Zusy.D6303B
GDataWin32.Trojan.PSE.1IAKRUN
AhnLab-V3Trojan/Win.BH.C4740788
McAfeeGenericRXPM-WI!12C205C947C9
MAXmalware (ai score=85)
MalwarebytesAdware.Agent.SFP.Generic
PandaTrj/CI.A
RisingTrojan.Kryptik!1.AA55 (CLASSIC)
FortinetW32/Kryptik.HATU!tr
AVGWin32:CrypterX-gen [Trj]

How to remove Zusy.405563 (B)?

Zusy.405563 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment