Malware

Zusy.539543 removal instruction

Malware Removal

The Zusy.539543 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.539543 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Zusy.539543?


File Info:

name: 32641CCE5EF57FEAEE1C.mlw
path: /opt/CAPEv2/storage/binaries/36640d9041a43b16110e151bccf3f5758b345af57b192db5145c170e05e7d677
crc32: 96AE6817
md5: 32641cce5ef57feaee1c3b7e07d94174
sha1: 3ceefc228113458db8fdf873ff7392593ead85d4
sha256: 36640d9041a43b16110e151bccf3f5758b345af57b192db5145c170e05e7d677
sha512: a433b2772f55d42179e60bcab57685babeae8417fa8688edafa430f499a5359687a7fbcb6e0a88eb84e7df8432d3ff60a1406f3d4cfaf73e3d7a912db6529d71
ssdeep: 6144:8pzQc0f7XP+g3AGJpWVzutjmI8nQOsPVKnvmb7/D26Mbj/R8SUHAgOTTMEtBTTlW:Y27/XvLWpu0nQOsPVKnvmb7/D26MHUHX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T133642A13AA11712FE642C4F02EA886A7792D2D7627907C077781FF2925B05ABF5B035F
sha3_384: 38b56172450f35b4d2e4206f81c53e82c538f3ee8f0a68b1dbb944445c73a17557de5443ee87386bdb4f56aeebd20519
ep_bytes: 6824394000e8eeffffff000000000000
timestamp: 2008-06-27 10:51:52

Version Info:

0: [No Data]

Zusy.539543 also known as:

BkavW32.AIDetectMalware
AVGWin32:Regrun-JL [Trj]
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.539543
FireEyeGeneric.mg.32641cce5ef57fea
SkyhighBehavesLike.Win32.VBObfus.fh
ALYacGen:Variant.Zusy.539543
MalwarebytesGeneric.Worm.AutoRun.DDS
SangforSuspicious.Win32.Save.vb
K7GWEmailWorm ( 0054d10f1 )
K7AntiVirusEmailWorm ( 0054d10f1 )
BaiduWin32.Worm.VB.oz
VirITTrojan.Win32.Generic.CGLJ
SymantecW32.Changeup
ESET-NOD32Win32/AutoRun.VB.APL
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.devi
BitDefenderGen:Variant.Zusy.539543
NANO-AntivirusTrojan.Win32.Jorik.cqkygj
AvastWin32:Regrun-JL [Trj]
TencentWorm.Win32.Vobfus.kax
EmsisoftGen:Variant.Zusy.539543 (B)
F-SecureTrojan.TR/Vobfus.jzka
DrWebTrojan.VbCrypt.150
VIPREGen:Variant.Zusy.539543
TrendMicroWORM_VOBFUS.SM5
Trapminemalicious.high.ml.score
SophosMal/SillyFDC-T
SentinelOneStatic AI – Malicious PE
VaristW32/Trojan.IIZ.gen!Eldorado
AviraTR/Vobfus.jzka
MAXmalware (ai score=87)
Antiy-AVLVirus/Win64.Expiro.rsrc
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus!pz
XcitiumWorm.Win32.VB.AUA@4o7zkg
ArcabitTrojan.Zusy.D83B97
ViRobotWorm.Win32.A.WBNA.294912.U
ZoneAlarmWorm.Win32.Vobfus.devi
GDataGen:Variant.Zusy.539543
GoogleDetected
AhnLab-V3Trojan/Win32.Jorik.R23549
Acronissuspicious
McAfeeVBObfus.by
VBA32BScope.Trojan.Diple
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallWORM_VOBFUS.SM5
RisingWorm.Autorun!1.99EA (CLASSIC)
IkarusTrojan.Vobfus
FortinetW32/CoinMiner.F
BitDefenderThetaGen:NN.ZevbaF.36804.uqZ@aG1P7@k
DeepInstinctMALICIOUS

How to remove Zusy.539543?

Zusy.539543 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment