Malware

How to remove “Heur.Zybut.1”?

Malware Removal

The Heur.Zybut.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Heur.Zybut.1 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Heur.Zybut.1?


File Info:

name: 46600F38755D9DFF79C3.mlw
path: /opt/CAPEv2/storage/binaries/aeca8de6c51e1464e96c188131171bec17491958c497a55fd979c2401ef754d8
crc32: 024F2026
md5: 46600f38755d9dff79c3b1068bc9365f
sha1: bdfab8ced6cc7931598e7d12b0b07e45334eabc7
sha256: aeca8de6c51e1464e96c188131171bec17491958c497a55fd979c2401ef754d8
sha512: df6b5a51067fc3a3c3b2edfa76f1aad605f4d9846e01df19205e65750fb1eb97f5e04b32352afc9cb655b7566b891230530ef3811ea6b26c2f0734cfb256538c
ssdeep: 384:DQy4RwDuWcZcDHJ7u5eqURx5w+8jHhGS4OSeNGWJkkx:caCWz4+8rSO3Jx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13C447C5BBB5212CBD51D0930D99358D29BFE8D332652037FCB08982A7CF0AC239C5875
sha3_384: a990186f2294e1fddb153814669680bde741e65b649076d5355edfd3ca7a09c8af267203cf1f8eb12adf4906bfc48d2b
ep_bytes: 558bec83ec0cc705a5b04300a0090000
timestamp: 2008-01-10 20:31:36

Version Info:

FileVersion: 3.8.7.1
ProductVersion: 1.7.4.9
FileDescription: africanthropus
CompanyName: flouncey
LegalCopyright: Knitter
ProductName: Canorousness
Translation: 0x0000 0x04b0

Heur.Zybut.1 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Zybut.1
FireEyeGeneric.mg.46600f38755d9dff
McAfeeGeneric-FAES!46600F38755D
CylanceUnsafe
K7AntiVirusBackdoor ( 003f4df21 )
K7GWBackdoor ( 003f4df21 )
Cybereasonmalicious.8755d9
BitDefenderThetaGen:NN.ZexaF.34712.qK0@aGlW8@fi
CyrenW32/Agent.OC.gen!Eldorado
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.ADEY
APEXMalicious
KasperskyHEUR:Backdoor.Win32.Generic
BitDefenderGen:Heur.Zybut.1
NANO-AntivirusTrojan.Win32.PWS.reyld
AvastWin32:MalOb-KC [Cryp]
Ad-AwareGen:Heur.Zybut.1
EmsisoftGen:Heur.Zybut.1 (B)
ComodoBackdoor.Win32.Shiz.BWWS@4n4fjv
McAfee-GW-EditionBehavesLike.Win32.Generic.dz
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/EncPk-AEC
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Shiz.btv
AviraTR/Crypt.XPACK.Gen
MicrosoftTrojan:Win32/Wacatac.B!ml
ViRobotBackdoor.Win32.A.Shiz.263680.M
GDataGen:Heur.Zybut.1
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Shiz.R21304
ALYacGen:Heur.Zybut.1
MAXmalware (ai score=80)
MalwarebytesMalware.Heuristic.1008
RisingTrojan.Zybut!1.9996 (CLASSIC)
YandexTrojan.GenAsa!3s7PJp8yfhc
FortinetW32/Shiz.NCF!tr
AVGWin32:MalOb-KC [Cryp]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Heur.Zybut.1?

Heur.Zybut.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment