Malware

Zusy.Elzob.22917 removal instruction

Malware Removal

The Zusy.Elzob.22917 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.Elzob.22917 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Zusy.Elzob.22917?


File Info:

name: CEF506D07F383D63B16B.mlw
path: /opt/CAPEv2/storage/binaries/d0286100bec817d7953f38fc25e70100fcca92ddc8b998135745678d193edd96
crc32: 158C0979
md5: cef506d07f383d63b16bb86f139c1cde
sha1: b8a9153a72bf6eb8513bdc9d846043f84f7437a0
sha256: d0286100bec817d7953f38fc25e70100fcca92ddc8b998135745678d193edd96
sha512: aeece8674425b17f66498334d33c723b645ba2febd8adc054f4e6a165bd850ea13f656d9694108b276671b48b3a43833039f42c675f1f0467a5edf7def7f4f24
ssdeep: 3072:AaH0vcveOQ5pFWlqKNIbFEwAQ0723+SZm20mtcNzcx5bj2kmEjWQzOaumy/VCPty:t00vZQrFWlqJ0M+Scm/xsEjxOeQtz1Ec
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16844E0BC5A26732EC17BE975E00B3903DBFE650A23222E4756DDC589334644BADCE44E
sha3_384: b5be4c9369c41e5d7423fa2827a36f385c9300719d30e6cb0aa33f2415ff6ae0ec3951e6080177c716a96004f0a9b9d7
ep_bytes: 558bec51b825524000b8255240008bd5
timestamp: 2013-01-17 22:30:45

Version Info:

CompanyName: Microsoft Corporation
DirectShow: Windows Media Player
FileDescription: Windows Media Player
FileVersion: 6.4.09.1125
InternalName: MPlayer2.exe
LegalCopyright: Copyright (C) 1992-1999 Microsoft Corp.
OriginalFilename: MPlayer2.exe
ProductName: Microsoft Windows Media Player
ProductVersion: 6.4.09.1125
Translation: 0x0409 0x04e4

Zusy.Elzob.22917 also known as:

LionicTrojan.Win32.Generic.4!c
DrWebTrojan.PWS.Panda.2401
FireEyeGeneric.mg.cef506d07f383d63
ALYacGen:Variant.Zusy.Elzob.22917
CylanceUnsafe
VIPRETrojan-PWS.Win32.Zbot.aql (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f0ce1 )
AlibabaTrojanPSW:Win32/Kryptik.cb19084d
K7GWTrojan-Downloader ( 0040f0ce1 )
Cybereasonmalicious.07f383
VirITTrojan.Win32.Agent.H
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.ASLE
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.Elzob.22917
NANO-AntivirusTrojan.Win32.Zbot.bxnbef
MicroWorld-eScanGen:Variant.Zusy.Elzob.22917
AvastWin32:Fareit-DL [Trj]
RisingMalware.Undefined!8.C (TFE:4:SN9WtcVed0J)
Ad-AwareGen:Variant.Zusy.Elzob.22917
EmsisoftGen:Variant.Zusy.Elzob.22917 (B)
ComodoTrojWare.Win32.Kryptik.NFEI@4urfiv
ZillyaTrojan.Kryptik.Win32.339873
McAfee-GW-EditionPWS-Zbot.gen.aua
SophosMal/Generic-R + Troj/Zbot-DUZ
IkarusTrojan.Win32.Reveton
GDataGen:Variant.Zusy.Elzob.22917
JiangminTrojan.Generic.dvmkx
WebrootW32.Cycbot.Gen
AviraTR/Crypt.ZPACK.Gen
ArcabitTrojan.Zusy.Elzob.D5985
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot!CI
TACHYONTrojan-Spy/W32.ZBot.274936
AhnLab-V3Spyware/Win32.Zbot.R51060
Acronissuspicious
McAfeePWS-Zbot.gen.aua
MAXmalware (ai score=100)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesMalware.AI.1263519350
APEXMalicious
TencentMalware.Win32.Gencirc.11d28ee6
YandexTrojan.Zusy!EWyeDM2fRJI
SentinelOneStatic AI – Malicious PE
FortinetW32/Zbot.DHN!tr
AVGWin32:Fareit-DL [Trj]
PandaTrj/Hexas.HEU
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Zusy.Elzob.22917?

Zusy.Elzob.22917 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment