Malware

How to remove “Zusy.519229”?

Malware Removal

The Zusy.519229 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.519229 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Zusy.519229?


File Info:

name: DBCC40FED598A297062F.mlw
path: /opt/CAPEv2/storage/binaries/f67abb4496d5f78c0206ad56cb7da45cdfbd76a6fadb26b073dfd75cfd4309cb
crc32: AB97D8FB
md5: dbcc40fed598a297062f2ab0d4a18123
sha1: 9e763d7a3386749ec9867a9bf6cc1fbc35152f73
sha256: f67abb4496d5f78c0206ad56cb7da45cdfbd76a6fadb26b073dfd75cfd4309cb
sha512: 95fe3773ba826a94b914450073bbd8f13c4d099136007a3bb48eff85ddd5e4e30950ba01deeeeafd8287baed11e0a8a8b64a2fa66a30759742790f6b6e4d14a5
ssdeep: 12288:zWBm+95nHfF2mgewFE5hD5Y4BeNCUucZD9UlGL1kfgjdkAsSOs:zWBz95ndbgfE5k4BeQBcZhU0sgjTsSOs
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T168C4E02577938033E19B02320E6BCAAA593A7C755B2A54C763E4B33E5E317D1DB3530A
sha3_384: 7f59870fd6776dc4c58c03f49ff226a7622756ef1d867ad98a5f3c44848295284c1df4c500e3bac32436abc01c63e93e
ep_bytes: e8d9650000e989feffff8bff558bec5d
timestamp: 2010-12-15 13:49:22

Version Info:

Comments: JPEG Image
FileDescription: JPEG Image
FileVersion: 6.1.7601.17514
ProductVersion: 6.1.7601.17514
Translation: 0x0409 0x04b0

Zusy.519229 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.519229
SkyhighBehavesLike.Win32.Generic.hc
McAfeeGenericRXLG-ZO!DBCC40FED598
MalwarebytesWapomi.Virus.FileInfector.DDS
ZillyaDropper.Agent.Win32.175568
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004e16831 )
K7GWTrojan ( 004e16831 )
Cybereasonmalicious.a33867
ArcabitTrojan.Zusy.D7EC3D
BitDefenderThetaGen:NN.ZexaF.36792.H02@a8VRZnji
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDropper.Agent.RHG
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Bskd-9753126-0
KasperskyBackdoor.Win32.Salgorea.a
BitDefenderGen:Variant.Zusy.519229
NANO-AntivirusTrojan.Win32.Agent.djzunh
AvastWin32:Agent-AYZG [Cryp]
TencentBackdoor.Win32.Salgorea.wa
EmsisoftGen:Variant.Zusy.519229 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Siggen6.24701
VIPREGen:Variant.Zusy.519229
FireEyeGeneric.mg.dbcc40fed598a297
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Agent.brds
WebrootW32.Malware.Gen
VaristW32/Agent.HQE.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan[Backdoor]/Win32.Salgorea.gen
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Agent.QGO@57p1tw
MicrosoftTrojan:Win32/Cerber.MPI!MTB
ViRobotTrojan.Win32.Agent.505344.F
ZoneAlarmBackdoor.Win32.Salgorea.a
GDataWin32.Trojan.PSE1.1R9720H
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R620327
VBA32Backdoor.Salgorea
ALYacGen:Variant.Zusy.519229
TACHYONTrojan/W32.Salgorea.547441
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.[OceanLotus]Salgorea!1.C3DC (CLASSIC)
IkarusTrojan-Dropper.Win32.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.AYZG!tr
AVGWin32:Agent-AYZG [Cryp]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Zusy.519229?

Zusy.519229 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment