Malware

What is “Zusy.411658”?

Malware Removal

The Zusy.411658 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.411658 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the AllaKore malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Zusy.411658?


File Info:

name: F3FDAF10932DC5D6AB67.mlw
path: /opt/CAPEv2/storage/binaries/9221470c77b46bcd457951ae3a3d31d60ad4602ea9d152d51d1e4f9a5b3bca3a
crc32: 6976E8FF
md5: f3fdaf10932dc5d6ab67bb8e0e20cfaf
sha1: 8b6745bb53ccc6cbf7ea04fc8c205728d5886023
sha256: 9221470c77b46bcd457951ae3a3d31d60ad4602ea9d152d51d1e4f9a5b3bca3a
sha512: c89d98e0a21b97104a87f30e557cf8a6e169a622e7a045df9422b3f86fbf996a91127740c5255f677db20f288d4ccb3bbc379cda082f20eba3d9c157404445f7
ssdeep: 196608:nnA6ZjgUaHZAF0/ZO8ASSSSSkSSSOfhCT8hw:nnAIK/ZOVSSSSSkSSSfT8h
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19896AE13B3806626D0670E371677AA94543B3F212B168C5A76FC6A8C8F35A417D7FE23
sha3_384: 880acb71a712efb27af6a73874d533bb857457c0b339f067fabb0d93813b6255d6a652c6e00a00ab37cfb15407596865
ep_bytes: 558bec83c4f0b8400b8600e8e814baff
timestamp: 2022-05-06 16:35:30

Version Info:

CompanyName: CreatiUPRPS Win Service
FileDescription: CreatiUPRPS Win Service
FileVersion: 3.3.2.0
InternalName: CreatiUPRPS Win Service
LegalCopyright: CreatiUPRPS Win Service
LegalTrademarks: CreatiUPRPS Win Service
OriginalFilename: CreatiUPRPS Win Service
ProductName: CreatiUPRPS Win Service
ProductVersion: 1.0.0.0
Comments: CreatiUPRPS Win Service
ProgramID: com.embarcadero.eraw
Translation: 0x1809 0x04e4

Zusy.411658 also known as:

BkavW32.Common.297F5C4F
LionicTrojan.Win32.Agent.Y!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.411658
SkyhighBehavesLike.Win32.Dropper.rc
ALYacBackdoor.RAT.AllaKore
MalwarebytesTrojan.Banker
VIPREGen:Variant.Zusy.411658
SangforBanker.Win32.Zusy.V6xc
K7AntiVirusSpyware ( 0057fa581 )
AlibabaTrojanSpy:Win32/Banker.fc633caf
K7GWSpyware ( 0057fa581 )
Cybereasonmalicious.b53ccc
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Spy.Banker.AEMG
KasperskyHEUR:Trojan-Banker.Win32.Agent.gen
BitDefenderGen:Variant.Zusy.411658
NANO-AntivirusTrojan.Win32.Banker.jxzgrx
AvastWin32:SpywareX-gen [Trj]
TencentMalware.Win32.Gencirc.13ead3a0
EmsisoftGen:Variant.Zusy.411658 (B)
ZillyaTrojan.Banker.Win32.137721
TrendMicroTrojan.Win32.BANKER.R002C0WA424
FireEyeGeneric.mg.f3fdaf10932dc5d6
SophosMal/Generic-S
MAXmalware (ai score=83)
GDataGen:Variant.Zusy.411658
JiangminTrojan.Banker.Agent.ery
WebrootW32.Trojan.Gen
GoogleDetected
VaristW32/ABSpyware.FDFM-5540
Antiy-AVLTrojan[Spy]/Win32.Banker
KingsoftWin32.Trojan-Banker.Agent.gen
XcitiumMalware@#1ax47fhholg54
ArcabitTrojan.Zusy.D6480A
ZoneAlarmHEUR:Trojan-Banker.Win32.Agent.gen
MicrosoftTrojan:Win32/Malgent!MSR
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R497694
McAfeeAllakoreRat!F3FDAF10932D
VBA32TScope.Trojan.Delf
Cylanceunsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.BANKER.R002C0WA424
RisingSpyware.Banker!8.8D (TFE:5:jFu8wpLfuqT)
IkarusTrojan-Spy.Win32.Banker
MaxSecureTrojan.Malware.73429889.susgen
FortinetW32/Banker.AEMG!tr.spy
BitDefenderThetaGen:NN.ZelphiCO.36744.@V0@aGPE8oMi
AVGWin32:SpywareX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Zusy.411658?

Zusy.411658 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment