Malware

Zusy.433616 (B) (file analysis)

Malware Removal

The Zusy.433616 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.433616 (B) virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Zusy.433616 (B)?


File Info:

name: D170BD63CC23FE58B54B.mlw
path: /opt/CAPEv2/storage/binaries/3fe6744657d122a7689b4f47fc9f4d1718a625ec8f9c87eafaf6eeceed1f2a80
crc32: 44345C42
md5: d170bd63cc23fe58b54bf57c4bf1f0f4
sha1: b41dee689cdb3b191ad07636b7a882e3215e745d
sha256: 3fe6744657d122a7689b4f47fc9f4d1718a625ec8f9c87eafaf6eeceed1f2a80
sha512: 75834b2df411b380f177296028c0b9ab9e7e234b90baa151b2f461114b8fa4aa90ef45731dd79ab6a5b937a8f6c2e000844b517d0f95aa516d9c150a93263dd2
ssdeep: 768:nt4vcGTnArp7bC5BGJdcn56W8reUXGj3mgI/GvsdkQ1VTQxw6Boj:nWvnA9PGvsDb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11B53F72369318876F45546F046B60B38F830D6A104BA96ABEFC4DEF02EB3B32DB5545D
sha3_384: db6f0d0dd4a7971ad6b3b1741a9b3dc455db4c0070ea62ab2ad2eaccd450ec87b65308f9c21ee9284cf5a34201412400
ep_bytes: e88b5e0000e8215e000033c0c3909090
timestamp: 2021-12-09 06:26:31

Version Info:

0: [No Data]

Zusy.433616 (B) also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.433616
ClamAVWin.Trojan.Generic-9907950-0
FireEyeGeneric.mg.d170bd63cc23fe58
ALYacGen:Variant.Zusy.433616
CylanceUnsafe
ZillyaDownloader.Agent.Win32.458157
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34606.dqW@a0DnmNn
CyrenW32/Agent.ENH.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.GHY
APEXMalicious
CynetMalicious (score: 100)
KasperskyVHO:Trojan.Win32.GenericML.xnet
BitDefenderGen:Variant.Zusy.433616
NANO-AntivirusTrojan.Win32.Razy.jjofts
AvastWin32:Evo-gen [Trj]
TencentTrojan.Win32.Agentb.wp
Ad-AwareGen:Variant.Zusy.433616
TACHYONTrojan/W32.Agent.63488.AXQ
EmsisoftGen:Variant.Zusy.433616 (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
DrWebTrojan.DownLoader44.17475
VIPREGen:Variant.Zusy.433616
McAfee-GW-EditionBehavesLike.Win32.RAHack.km
Trapminemalicious.high.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1ETEWJE
JiangminTrojan.Agent.dtbb
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASBOL.C4EC
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Dropper/Win.Generic.R462985
Acronissuspicious
McAfeeGenericRXRQ-HV!D170BD63CC23
MAXmalware (ai score=86)
MalwarebytesTrojan.Downloader
RisingDownloader.Agent!1.DEFD (CLASSIC)
YandexTrojan.Agent!epU8Fi9m7Uo
IkarusTrojan.Win32
MaxSecureTrojan.Malware.82199810.susgen
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.89cdb3
PandaTrj/GdSda.A

How to remove Zusy.433616 (B)?

Zusy.433616 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment