Malware

Zusy.77094 removal tips

Malware Removal

The Zusy.77094 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.77094 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Zusy.77094?


File Info:

name: 76C62DFF2159A77F9DF8.mlw
path: /opt/CAPEv2/storage/binaries/775b16e904cc53c86eeb42adc87549b10926137009445882478571e7aa003157
crc32: 7B86337D
md5: 76c62dff2159a77f9df8516e9a5b3cb0
sha1: 0c8a46a418c3163fe151b83ec883036e82d0638a
sha256: 775b16e904cc53c86eeb42adc87549b10926137009445882478571e7aa003157
sha512: 9a3b7eefada6cb699e4f795f89e24ea4d01db0e097691a8bdbe144dba310c04222d1bb213ccb1c1b3a7c04c084324528c861f5ecc34fcedea70f171057ad4387
ssdeep: 3072:OiFRf6xBN/9S4YsIxqVAmDzNsyhNrlZPITUNya9Uyg5bL1E31Qa8w7vOuR1UQOEz:fKxrEonRbjrllIT5mqQ31JnRuS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CF24126A06BA4BE4E8B700FAE5E5C9C808FDCA5523C5179B56C60CF42D35E434BB4F1A
sha3_384: 1495ecc386133b771759e47ebda37fe2002d570184e2ad87ee91a222055c021386ea2bae143f8d47c2a38d6528334458
ep_bytes: 558bec81ec00010000b961260000894d
timestamp: 2012-11-29 19:19:46

Version Info:

ProductVersion: 185.242.61788
Translation: 0x0409 0x04b0

Zusy.77094 also known as:

BkavW32.FamVT.Yakes.003.Worm
LionicTrojan.Win32.Zbot.lVDm
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader9.5204
MicroWorld-eScanGen:Variant.Zusy.77094
FireEyeGeneric.mg.76c62dff2159a77f
CAT-QuickHealFraudTool.Security
ALYacGen:Variant.Zusy.77094
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.144314
SangforTrojan.Win32.Bulta.rfn
K7AntiVirusTrojan ( 0040f8b21 )
AlibabaTrojanSpy:Win32/Bulta.fcbe5130
K7GWTrojan ( 0040f8b21 )
Cybereasonmalicious.f2159a
ArcabitTrojan.Zusy.D12D26
BitDefenderThetaGen:NN.ZexaF.34212.nu1@aSIqkRfO
VirITTrojan.Win32.Generic.TDJ
CyrenW32/Zbot.OL.gen!Eldorado
SymantecTrojan.FakeAV!gen115
ESET-NOD32Win32/Spy.Zbot.ABA
TrendMicro-HouseCallTSPY_ZBOT.SMODN
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-57948
KasperskyTrojan-Spy.Win32.Zbot.raov
BitDefenderGen:Variant.Zusy.77094
NANO-AntivirusTrojan.Win32.Zbot.crvczw
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
AvastWin32:Kryptik-OEU [Trj]
TencentTrojan.Win32.Zbot.d
Ad-AwareGen:Variant.Zusy.77094
EmsisoftGen:Variant.Zusy.77094 (B)
ComodoTrojWare.Win32.Kryptik.BQD@55o2q6
BaiduWin32.Trojan.Kryptik.dk
VIPRETrojan-Spy.Win32.Zbot.gen
TrendMicroTSPY_ZBOT.SMODN
McAfee-GW-EditionPWSZbot-FLM!76C62DFF2159
SophosMal/Generic-R + Troj/Zbot-HGR
IkarusTrojan.Win32.Yakes
JiangminTrojanSpy.Zbot.eahg
MaxSecureTrojan.Yakes.DGen
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.69F3C6
KingsoftWin32.Troj.Zbot.ra.(kcloud)
MicrosoftTrojan:Win32/Bulta!rfn
ZoneAlarmTrojan-Spy.Win32.Zbot.raov
GDataGen:Variant.Zusy.77094
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kazy.R92409
Acronissuspicious
McAfeePWSZbot-FLM!76C62DFF2159
TACHYONTrojan-Spy/W32.ZBot.214209
VBA32BScope.Malware-Cryptor.Hlux
MalwarebytesBackdoor.Agent.RND
APEXMalicious
RisingTrojan.Bulta!8.35D (CLOUD)
YandexTrojan.Agent!qYCBTEteFsc
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_53%
FortinetW32/Kryptik.CAAF!tr
AVGWin32:Kryptik-OEU [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Zusy.77094?

Zusy.77094 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment