Malware

About “Zusy.320090” infection

Malware Removal

The Zusy.320090 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.320090 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Zusy.320090?


File Info:

crc32: BA02B44B
md5: bc78dd83071e1e8178d12baa1669b060
name: BC78DD83071E1E8178D12BAA1669B060.mlw
sha1: 3a558a77b35eb945f1409b7f536ff7d0ae156858
sha256: b6d6cbf6362e4bc6a49a79e20f90983b63d897cb2a02963ce59440d4e4bd63c2
sha512: 4c37f58f6faa134d707448c976035e64e6d4971c2e7c477410e2451aa87f6bc508af86178b0ba3ae00869ca3311674c5959cfd9500cc84f947f3b092bfdd9c7a
ssdeep: 6144:AVXdFgHOeWq9pMAAkdTTUBYIpl16bjLUoT:AVt8OUjhTUBrlcbjo
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2013 Nero AG and its licensors
InternalName: Nero DiscMerge
FileVersion: 15,0,25,0
CompanyName: Nero AG
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Nero DiscMerge
SpecialBuild: 15,0,25,0
ProductVersion: 15,0,25,0
FileDescription: Nero DiscMerge Application
OriginalFilename: NeroDiscMerge.exe
Translation: 0x0409 0x04e4

Zusy.320090 also known as:

K7AntiVirusTrojan ( 0051e4491 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.22697
CynetMalicious (score: 85)
CAT-QuickHealDownldr.Freepds.MUE.ZZ5
ALYacGen:Variant.Zusy.320090
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Tovicrypt.d4a94e85
K7GWTrojan ( 0051e4491 )
Cybereasonmalicious.3071e1
CyrenW32/Tovicrypt.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.DPXE
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zusy.320090
NANO-AntivirusTrojan.Win32.HoPo.evrjua
SUPERAntiSpywareRansom.Filecoder/Variant
MicroWorld-eScanGen:Variant.Zusy.320090
TencentMalware.Win32.Gencirc.10b58bef
Ad-AwareGen:Variant.Zusy.320090
SophosML/PE-A + Mal/Swizzor-D
ComodoMalware@#22vdyy67uhgpk
BitDefenderThetaGen:NN.ZexaF.34608.ty0@amHyaxvi
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_Crypmic-1
McAfee-GW-EditionGenericRXDG-GU!BC78DD83071E
FireEyeGeneric.mg.bc78dd83071e1e81
EmsisoftGen:Variant.Zusy.320090 (B)
AviraHEUR/AGEN.1110705
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Tovicrypt.A
ArcabitTrojan.Zusy.D4E25A
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Zusy.320090
AhnLab-V3Trojan/Win32.CryptXXX.R184966
Acronissuspicious
McAfeeGenericRXDG-GU!BC78DD83071E
MAXmalware (ai score=100)
VBA32BScope.Trojan.Bagsu
MalwarebytesMalware.AI.182469934
PandaTrj/Genetic.gen
TrendMicro-HouseCallMal_Crypmic-1
RisingRansom.Tovicrypt!8.9F4B (CLOUD)
YandexTrojan.GenAsa!r09NXtpT7sw
IkarusTrojan-Ransom.Cryptprojectxxx
FortinetW32/Kryptik.FNZR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Generic/Trojan.7f6

How to remove Zusy.320090?

Zusy.320090 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment