Trojan

About “Trojan:Win32/Zusy.SPKL!MTB” infection

Malware Removal

The Trojan:Win32/Zusy.SPKL!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zusy.SPKL!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Saami
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/Zusy.SPKL!MTB?


File Info:

name: 46FA1BBA8D146D9E946F.mlw
path: /opt/CAPEv2/storage/binaries/7b9e3a1daae553787702cc7245c8aa6d569cbf97a054e6e7a1248c071eb9d7d4
crc32: 7758353F
md5: 46fa1bba8d146d9e946f7bd7cf3090f1
sha1: 345eb9663ecba78173e1c42652439c3f275fcc52
sha256: 7b9e3a1daae553787702cc7245c8aa6d569cbf97a054e6e7a1248c071eb9d7d4
sha512: befd5474bf673047b35b4f581e35714a73238742569a83c7128e4d6581463e5b7e24d0ee656f69c4ba678179052adba367b1617c0756769c807ea5d16769e533
ssdeep: 3072:kZVarLBkgSdn9jFjYSWgCZ9jWEHmknrbwKm7rUx07GtX+rB05Yu1yNh:IGBkg8JjYB+EHmUJm7oLl+rB5ey
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A1444C1362D17C61E5275A328E2EC6F4361EFD918F293BEA1615AB3F05701F2C27270A
sha3_384: 413a277cfe66b46b9fd147217b347cec87e04fd10269b708f0e9f814940f22fdb32832aa092bda1a5b39bf8fe17554e5
ep_bytes: e8293a0000e989feffffff35acfe4200
timestamp: 2022-09-13 11:30:38

Version Info:

FileDescriptions: Butts
InternalName: Buckiyarn.exe
LegalTrademark1: Gurumess
LegalTrademarks2: Gunshutting
OriginalFilename: Buskebaser.exe
ProductVersion: 76.47.92.28
Translation: 0x0709 0x04e2

Trojan:Win32/Zusy.SPKL!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Stealer.12!c
DrWebTrojan.Siggen21.64637
MicroWorld-eScanGen:Variant.Zusy.518555
ClamAVWin.Dropper.Tofsee-10013972-0
FireEyeGeneric.mg.46fa1bba8d146d9e
CAT-QuickHealRansom.Stop.P5
SkyhighBehavesLike.Win32.Generic.dh
McAfeeGenericRXWL-IR!46FA1BBA8D14
Cylanceunsafe
ZillyaTrojan.Kryptik.Win32.4504679
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Stealer.164573a9
K7GWTrojan ( 005adae81 )
K7AntiVirusTrojan ( 005adae81 )
VirITTrojan.Win32.Genus.UBR
SymantecML.Attribute.HighConfidence
ElasticWindows.Trojan.Smokeloader
ESET-NOD32a variant of Win32/Kryptik.HVEU
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Variant.Zusy.518555
NANO-AntivirusTrojan.Win32.Kryptik.kdfkjf
AvastWin32:BotX-gen [Trj]
TencentTrojan.Win32.Obfuscated.gen
TACHYONTrojan-Spy/W32.InfoStealer.262144.D
EmsisoftGen:Variant.Zusy.518555 (B)
F-SecureHeuristic.HEUR/AGEN.1366024
VIPREGen:Variant.Zusy.518555
TrendMicroTrojanSpy.Win32.STEALC.YXDKHZ
Trapminemalicious.high.ml.score
SophosTroj/Krypt-ACJ
IkarusTrojan-Ransom.StopCrypt
GDataGen:Variant.Zusy.518555
JiangminTrojanSpy.Windigo.amd
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1366024
Antiy-AVLTrojan/Win32.Kryptik
KingsoftWin32.Troj.Undef.a
ArcabitTrojan.Zusy.D7E99B
ViRobotTrojan.Win.Z.Zusy.262144.DN
ZoneAlarmHEUR:Trojan-Spy.Win32.Stealer.gen
MicrosoftTrojan:Win32/Zusy.SPKL!MTB
VaristW32/Stealer.GM.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R621085
VBA32TrojanRansom.Stealc
ALYacGen:Variant.Zusy.518555
MAXmalware (ai score=85)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.STEALC.YXDKHZ
RisingTrojan.SmokeLoader!1.E66C (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.73793603.susgen
FortinetW32/Kryptik.HVEX!tr
AVGWin32:BotX-gen [Trj]
Cybereasonmalicious.63ecba
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Zusy.SPKL!MTB?

Trojan:Win32/Zusy.SPKL!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment