Malware

Zusy.539059 (file analysis)

Malware Removal

The Zusy.539059 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.539059 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Executable file is packed/obfuscated with Themida
  • Authenticode signature is invalid
  • Binary file triggered YARA rule
  • Anomalous binary characteristics

How to determine Zusy.539059?


File Info:

name: 820965A380BD95192949.mlw
path: /opt/CAPEv2/storage/binaries/fb5218ec375d23527da3156dcfc0cf4dece9ea573ce26ea5528c379ceeb68fbc
crc32: D23DA104
md5: 820965a380bd951929497c18b9d20111
sha1: 150b65f990496e09965a41f4b3d91e26adaeb27a
sha256: fb5218ec375d23527da3156dcfc0cf4dece9ea573ce26ea5528c379ceeb68fbc
sha512: 92d25ebf748507d963bb628c3dcdf20a2184deea09e20f89ab9161e0236bd375fa75c08d64e9aa602790f8eddc06029df1202ee6818b59cda06386455ff21a20
ssdeep: 196608:RaWrnZCxyDwZ9YlQWPqTy129OIS6apbj7Z:R/cxyDi9YlQWSg2oISfpbfZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A86633C5547CF42EF0DFE2B015B7A232598808A2C547B5E8CBBFAD9B40B612D67F111A
sha3_384: 9685218ac59e1213c5c0eead8f0fa4a3c450a3ba9519e74e750377d5f6bfed0e3b901796e996e09a7a840e6bf14bf4c0
ep_bytes: e84b0100005389e3538b73088b7b10fc
timestamp: 2024-04-27 14:50:32

Version Info:

0: [No Data]

Zusy.539059 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.539059
FireEyeGeneric.mg.820965a380bd9519
SkyhighBehavesLike.Win32.Generic.vc
SangforTrojan.Win32.Save.a
BitDefenderThetaGen:NN.ZexaF.36804.@NW@aaq9Qun
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.Themida.CQ suspicious
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyVHO:Trojan.Win32.Sdum.gen
BitDefenderGen:Variant.Zusy.539059
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
EmsisoftGen:Variant.Zusy.539059 (B)
VIPREGen:Variant.Zusy.539059
Trapminemalicious.high.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=87)
ArcabitTrojan.Zusy.D839B3
ZoneAlarmVHO:Trojan.Win32.Sdum.gen
GDataGen:Variant.Zusy.539059
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R636308
VBA32BScope.Backdoor.Bladabindi
PandaTrj/Genetic.gen
RisingTrojan.Generic@AI.100 (RDML:4/cDHYUtQisBbMXwbEB2SA)
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Zusy.539059?

Zusy.539059 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment