Malware

Zusy.411600 removal instruction

Malware Removal

The Zusy.411600 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.411600 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes its original binary from disk

How to determine Zusy.411600?


File Info:

name: EA141F16FB7939111B3C.mlw
path: /opt/CAPEv2/storage/binaries/46d3ceb5bff4331e675146335c91bbac43c81126864710879efe16bf9a9e71a6
crc32: B371F954
md5: ea141f16fb7939111b3c0f6077c4e547
sha1: ea94bce961205b447b7742a9c5bf524d6b0bf0c8
sha256: 46d3ceb5bff4331e675146335c91bbac43c81126864710879efe16bf9a9e71a6
sha512: 09785ef7964d0696347e5321db12d70f65d98c89fddc289031a61281ab40df8e8014a287ab0bd932fdfc4e4b2a194ead2a4dc3410734229efb3bfad5440ddae0
ssdeep: 24576:T9PgXePQhN/YVtc266IOHk4CoU9b4waUCl5rYr:tgXePQhWVtcdlO9CoU95Ysr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17C35BE5AA485CC3BD8CA543DAC6B0235BB323A937D53740E5E74FB08F8A5A543C5E782
sha3_384: ece84a58949950a122aef39be0689b3dac36fa4effa539f65d931627f29ec75c7d047a9dcb33bcb952e26902bda6f33d
ep_bytes: f8731baddcdf13ef658e622d669e3db5
timestamp: 2021-12-27 13:04:31

Version Info:

FileVersion: 1.0.0.0
FileDescription: Windows 配置程序
ProductName: Windows 核心进程
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Zusy.411600 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.411600
FireEyeGeneric.mg.ea141f16fb793911
McAfeeFlyagent.d
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040f54a1 )
K7GWTrojan ( 0040f54a1 )
Cybereasonmalicious.6fb793
BitDefenderThetaGen:NN.ZexaF.34114.fr1@aOhYbngb
CyrenW32/S-ea8e18be!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Flyagent.NGX
APEXMalicious
ClamAVWin.Malware.FlyAgent-9850229-1
KasperskyVHO:Trojan.Win32.Fsysna.gen
BitDefenderGen:Variant.Zusy.411600
NANO-AntivirusVirus.Win32.Agent.dvixmz
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Flyagent.wa
Ad-AwareGen:Variant.Zusy.411600
EmsisoftGen:Variant.Zusy.411600 (B)
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosGeneric ML PUA (PUA)
IkarusTrojan.Win32.FlyAgent
GDataWin32.Trojan.Flyagent.A
AviraTR/Redcap.jfyzu
Antiy-AVLTrojan/Generic.ASMalwS.34FE169
ArcabitTrojan.Zusy.D647D0
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R463145
Acronissuspicious
VBA32BScope.Trojan.Dynamer
ALYacGen:Variant.Zusy.411600
MAXmalware (ai score=80)
MalwarebytesTrojan.MalPack.FlyStudio
RisingTrojan.FlyAgent!1.DAFB (RDMK:cmRtazr8prOl95llVnh4L+J9LrtF)
YandexTrojan.GenAsa!UMACS2Wk+V8
SentinelOneStatic AI – Malicious PE
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.BELF!tr
AVGWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Zusy.411600?

Zusy.411600 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment