Malware

What is “Zusy.8177”?

Malware Removal

The Zusy.8177 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.8177 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Zusy.8177?


File Info:

crc32: 640D39A3
md5: a7978c623b895dbbf4ffc8471d7b10ae
name: A7978C623B895DBBF4FFC8471D7B10AE.mlw
sha1: 31972dfe5dc8e416a52e490aab85f11ad6c9b9ca
sha256: bca7ce32b665b54f9fc1235e566ee711f187aa27eac593f488223bf3a45c0287
sha512: 9de90c61579360c27384a786fefa0361351f0c1f3c44034b354a49427a6cfea03bbbe273a8c4a58784cb863f3d449c6a5ab52e7f8351b315d8643cf470a0f4d5
ssdeep: 1536:9pwsybyoNJ9yYfC9lWc0Q6LflH+k+k4Eg526Gn:fQbPJ9R8W7P+kA23
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: Nonprofit organization offering health, educational, and distance learning Internet broadcasting services
InternalName: MSTBFILE
FileVersion: 1.00
CompanyName: Nonprofit organization offering health, educational, and distance learning Internet broadcasting services
LegalTrademarks: Nonprofit organization offering health, educational, and distance learning Internet broadcasting services
Comments: Nonprofit organization offering health, educational, and distance learning Internet broadcasting services
ProductName: Nonprofit organization offering health, educational, and distance learning Internet broadcasting services
ProductVersion: 1.00
FileDescription: Nonprofit organization offering health, educational, and distance learning Internet broadcasting services
OriginalFilename: MSTBFILE.EXE

Zusy.8177 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Gimemo.j!c
DrWebTrojan.Winlock.6486
CynetMalicious (score: 100)
ALYacGen:Variant.Zusy.8177
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaRansom:Win32/Blocker.a2801b44
Cybereasonmalicious.23b895
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.SFK
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Ransom.Win32.Blocker.kobm
BitDefenderGen:Variant.Zusy.8177
NANO-AntivirusTrojan.Win32.Gimemo.tfzkb
ViRobotTrojan.Win32.A.Gimemo.64318.A
MicroWorld-eScanGen:Variant.Zusy.8177
TencentWin32.Trojan.Gimemo.Lnnz
Ad-AwareGen:Variant.Zusy.8177
SophosML/PE-A + Troj/Gataka-E
ComodoMalware@#cnzk8edg06yr
BitDefenderThetaAI:Packer.77EA3CCD20
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Backdoor.kc
FireEyeGeneric.mg.a7978c623b895dbb
EmsisoftGen:Variant.Zusy.8177 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Gimemo.daw
WebrootW32.Trojan.Gen
AviraTR/Crypt.PEPM.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.9B2EB7
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Loktrom.B
ArcabitTrojan.Zusy.D1FF1
SUPERAntiSpywareTrojan.Agent/Gen-Bifrose
GDataGen:Variant.Zusy.8177
TACHYONTrojan/W32.Gimemo.64318
AhnLab-V3Backdoor/Win32.Bifrose.R64580
McAfeeArtemis!A7978C623B89
MAXmalware (ai score=100)
VBA32SScope.Trojan-Ransom.Winlock.5612
PandaGeneric Malware
YandexTrojan.Gimemo!pFTvd1oTQOY
IkarusTrojan.Win32.Ransom
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.S!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HxEAEpsA

How to remove Zusy.8177?

Zusy.8177 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment