This article has been created to help explain what is the Zusy Trojan and how to remove it from your computer effectively.
A new Trojan horse has been detected to spread at an alarming rate that surpasses even the WannaCry infection. The malware, called Zusy has been detected to replicate via a worm and then drop what appears to be a cryptocurrency miner, known as Tiggre (other name is Digmein), which aims to overload the CPU and GPU of the affected computers in order to obtain tokens at their expense and credit them to the cyber-crooks behind this outbreak. In case your computer has been infected by the Zeus Trojan, we recommend that you read this article as it will help you remove this malware and restore your PC’s performance to normal.
Threat Summary
Name | Zusy Trojan |
Type | Trojan Horse / Worm |
Short Description | An advanced worm, spreading the Zusy Trojan which downloads different malware on infected computers. |
Symptoms | All of your data on your computer may be compromised and your PC may experience slow-downs and have it’s CPU and GPU running on their limits. |
Distribution Method | Replicates automatically from infected machines to infected machines. Able to migrate to different networks. |
Detection Tool |
See If Your System Has Been Affected by malware
Download
Malware Removal Tool
|
User Experience | Join Our Forum to Discuss Zusy Trojan. |
Zusy Virus – Distribution
In order to be widespread on a serious level, the Zusy Virus uses a worm infection, which has been reported at VirusTotal and uploaded on Twitter by researcher Vess (@VessOnSecurity ).
Source: VirusTotal
The Zusy malware may use advanced exploits since researchers have reported it in VT as being highly evasive. One report by PayloadSecurity indicateds the following replication URLs in relation to the Zusy virus:
PayloadSecurity
2018-08-14
#evasivesubmitname:”ca71f8a79f8ed255bf03679504813c6a.dll.bin”
falcon-threatscore:100/100
memurl:”Heuristic match: down.0814ok.info,Pattern match: hxxp://js.0814ok.info:280/v.sct match: hxxp://wmi.0814ok.info:8888/kill.html;http,Pattern match: hxxp://js.0814ok.info:280/v.sct”
In addition to this, the malware may also have the capability of hijacking flash drives and other external memory carriers that copy scripts that allow for the infection to take place by exploiting AutoPlay in Windows.
Zusy Trojan – Analysis
The Zusy Trojan is the type of threat which aims to drop it’s payloaad files. The payload fils have random names and are also located in folders with random names. The folders are created in the %AppData% directory:
→ %AppData%\{random}\{random file}.exe – also detected as TSPY_ZBOT.ZUSY
%AppData%\{random}\{random file 2}.{random extension}
%AppData%\{random}\{random file 3}.tmp
Once this is done, the Zusy virus then creates an autostart type of registry entry in the following registry sub-key:
→ HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Run
The entry is set to run the randomly named .exe file, we mentioned above. Besides these modifications, the Trojan also adds registry entries in the following Windows sub-keys:
→ HKEY_CURRENT_USER\Software\Microsoft\
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfile\AuthorizedApplications\
List %Windows%\explorer.exe = “%Windows%\explorer.exe:*:Enabled:Windows Explorer”
→ HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings
WarnonBadCertRecving = “0”
→ HKEY_CURRENT_USER\Software\Microsoft\
Windows\CurrentVersion\Internet Settings
EnableSPDY3_0 = “0”
The malware then connects to what appears to be the following malcious URLs:
→ hxxp://js.0814ok.info:280/v.sct match: hxxp://wmi.0814ok.info:8888/kill.html;http, hxxp://js.0814ok.info:280/v.sct
From there it may download a CryptoCurrency miner virus, known as the Tiggre miner (W32/Tiggre), which aslo drops malicious files in the %AppData% directory and begins connecting to a remote server in order to begin mining for cryptocurrencies by utilizing your CPU and GPU to almost a 100%, which results in your PC starting to slow down at an alarming rate.
In addition to this, since it’s also a spyware, the Zusy Trojan may also use it’s tracking technologies to steal different type of information from your PC, based on how the virus is configured. The types of data can be the following:
- Log your keystrokes.
- Steal saved passwords.
- Obtain files from your PC.
- Take over your communication logs (Chat history, etc.).
- Take screenshots.
- Control your web camera.
Furthermore, the Zusy virus may also delete its main malicious file after infecting your computer and continue to spread on another PC’s on a network level of replication (via intermediary and end devices, like routers, switches, etc.). This is done for malware researchers to prevent discovering the infection and hence creating a kill switch of it.
Remove Zusy Trojan from Your PC
If you want to remove the Zusy Trojan completely from your computer, your can do several different actions that isolate it’s activity. The first one is to boot your comptuer into safe mode and then hunt for the registry sub-keys and objects of the virus manually. This can be done by following the manual removal instructions underneath this article.
However, if manual removal does not seem to be working for you or you want to be fully sure that the Zusy virus and all the related miner viruses it drops on your PC are gone for good, be advised that the recommended removal method to go for is automatic removal by scanning your PC with a powerful anti-malware program. Such tool is created to best help you out to remove all of the objects, related to Zusy virus on your PC.
- Guide 1: How to Remove Zusy Trojan from Windows.
- Guide 2: Get rid of Zusy Trojan on Mac OS X.
- Guide 3: Remove Zusy Trojan in Google Chrome.
- Guide 4: Erase Zusy Trojan from Mozilla Firefox.
- Guide 5: Uninstall Zusy Trojan from Microsoft Edge.
- Guide 6: Remove Zusy Trojan from Safari.
- Guide 7: Eliminate Zusy Trojan from Internet Explorer.
- Guide 8: Disable Zusy Trojan Push Notifications in Your Browsers.
Windows Mac OS X Google Chrome Mozilla Firefox Microsoft Edge Safari Internet Explorer Stop Push Pop-ups
How to Remove Zusy Trojan from Windows.
Step 1: Boot Your PC In Safe Mode to isolate and remove Zusy Trojan





Step 2: Uninstall Zusy Trojan and related software from Windows
Here is a method in few easy steps that should be able to uninstall most programs. No matter if you are using Windows 10, 8, 7, Vista or XP, those steps will get the job done. Dragging the program or its folder to the recycle bin can be a very bad decision. If you do that, bits and pieces of the program are left behind, and that can lead to unstable work of your PC, errors with the file type associations and other unpleasant activities. The proper way to get a program off your computer is to Uninstall it. To do that:



Step 3: Clean any registries, created by Zusy Trojan on your computer.
The usually targeted registries of Windows machines are the following:
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
- HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce
You can access them by opening the Windows registry editor and deleting any values, created by Zusy Trojan there. This can happen by following the steps underneath:



Before starting "Step 4", please boot back into Normal mode, in case you are currently in Safe Mode.
This will enable you to install and use SpyHunter 5 successfully.
Windows Mac OS X Google Chrome Mozilla Firefox Microsoft Edge Safari Internet Explorer Stop Push Pop-ups
Get rid of Zusy Trojan from Mac OS X.
Step 1: Uninstall Zusy Trojan and remove related files and objects
1. Hit the ⇧+⌘+U keys to open Utilities. Another way is to click on “Go” and then click “Utilities”, like the image below shows:
- Go to Finder.
- In the search bar type the name of the app that you want to remove.
- Above the search bar change the two drop down menus to “System Files” and “Are Included” so that you can see all of the files associated with the application you want to remove. Bear in mind that some of the files may not be related to the app so be very careful which files you delete.
- If all of the files are related, hold the ⌘+A buttons to select them and then drive them to “Trash”.
In case you cannot remove Zusy Trojan via Step 1 above:
In case you cannot find the virus files and objects in your Applications or other places we have shown above, you can manually look for them in the Libraries of your Mac. But before doing this, please read the disclaimer below:
You can repeat the same procedure with the following other Library directories:
→ ~/Library/LaunchAgents
/Library/LaunchDaemons
Tip: ~ is there on purpose, because it leads to more LaunchAgents.
Step 2: Scan for and remove Zusy Trojan files from your Mac
When you are facing problems on your Mac as a result of unwanted scripts and programs such as Zusy Trojan, the recommended way of eliminating the threat is by using an anti-malware program. SpyHunter for Mac offers advanced security features along with other modules that will improve your Mac’s security and protect it in the future.
Windows Mac OS X Google Chrome Mozilla Firefox Microsoft Edge Safari Internet Explorer Stop Push Pop-ups
Remove Zusy Trojan from Google Chrome.
Step 1: Start Google Chrome and open the drop menu
Step 2: Move the cursor over "Tools" and then from the extended menu choose "Extensions"
Step 3: From the opened "Extensions" menu locate the unwanted extension and click on its "Remove" button.
Step 4: After the extension is removed, restart Google Chrome by closing it from the red "X" button at the top right corner and start it again.
Windows Mac OS X Google Chrome Mozilla Firefox Microsoft Edge Safari Internet Explorer Stop Push Pop-ups
Erase Zusy Trojan from Mozilla Firefox.
Step 1: Start Mozilla Firefox. Open the menu window
Step 2: Select the "Add-ons" icon from the menu.
Step 3: Select the unwanted extension and click "Remove"
Step 4: After the extension is removed, restart Mozilla Firefox by closing it from the red "X" button at the top right corner and start it again.
Windows Mac OS X Google Chrome Mozilla Firefox Microsoft Edge Safari Internet Explorer Stop Push Pop-ups
Uninstall Zusy Trojan from Microsoft Edge.
Step 1: Start Edge browser.
Step 2: Open the drop menu by clicking on the icon at the top right corner.
Step 3: From the drop menu select "Extensions".
Step 4: Choose the suspected malicious extension you want to remove and then click on the gear icon.
Step 5: Remove the malicious extension by scrolling down and then clicking on Uninstall.
Windows Mac OS X Google Chrome Mozilla Firefox Microsoft Edge Safari Internet Explorer Stop Push Pop-ups
Remove Zusy Trojan from Safari.
Step 1: Start the Safari app.
Step 2: After hovering your mouse cursor to the top of the screen, click on the Safari text to open its drop down menu.
Step 3: From the menu, click on "Preferences".
Step 4: After that, select the 'Extensions' Tab.
Step 5: Click once on the extension you want to remove.
Step 6: Click 'Uninstall'.
A pop-up window will appear asking for confirmation to uninstall the extension. Select 'Uninstall' again, and the Zusy Trojan will be removed.
Windows Mac OS X Google Chrome Mozilla Firefox Microsoft Edge Safari Internet Explorer Stop Push Pop-ups
Eliminate Zusy Trojan from Internet Explorer.
Step 1: Start Internet Explorer.
Step 2: Click on the gear icon labeled 'Tools' to open the drop menu and select 'Manage Add-ons'
Step 3: In the 'Manage Add-ons' window.
Step 4: Select the extension you want to remove and then click 'Disable'. A pop-up window will appear to inform you that you are about to disable the selected extension, and some more add-ons might be disabled as well. Leave all the boxes checked, and click 'Disable'.
Step 5: After the unwanted extension has been removed, restart Internet Explorer by closing it from the red 'X' button located at the top right corner and start it again.
Remove Push Notifications caused by Zusy Trojan from Your Browsers.
Turn Off Push Notifications from Google Chrome
To disable any Push Notices from Google Chrome browser, please follow the steps below:
Step 1: Go to Settings in Chrome.
Step 2: In Settings, select “Advanced Settings”:
Step 3: Click “Content Settings”:
Step 4: Open “Notifications”:
Step 5: Click the three dots and choose Block, Edit or Remove options:
Remove Push Notifications on Firefox
Step 1: Go to Firefox Options.
Step 2: Go to “Settings”, type “notifications” in the search bar and click "Settings":
Step 3: Click “Remove” on any site you wish notifications gone and click “Save Changes”
Stop Push Notifications on Opera
Step 1: In Opera, press ALT+P to go to Settings
Step 2: In Setting search, type “Content” to go to Content Settings.
Step 3: Open Notifications:
Step 4: Do the same as you did with Google Chrome (explained below):
Eliminate Push Notifications on Safari
Step 1: Open Safari Preferences.
Step 2: Choose the domain from where you like push pop-ups gone and change to "Deny" from "Allow".