Malware

About “Zusy.546156” infection

Malware Removal

The Zusy.546156 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.546156 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Zusy.546156?


File Info:

name: 5C98FE8833BE466DAB1B.mlw
path: /opt/CAPEv2/storage/binaries/2ccd76923f9bafe93b1bddab837afe1a2379501c99d19aabfff01f92a0d72357
crc32: 27A9C43B
md5: 5c98fe8833be466dab1b081dc1b01578
sha1: 16d09c2128c4c26d0a68327261eef2fe1175fccc
sha256: 2ccd76923f9bafe93b1bddab837afe1a2379501c99d19aabfff01f92a0d72357
sha512: f39f194ff1e112a8c16a972d2b8919927534130e66a4315e81a965e4628768e55a04cec0f84ad24659e9e2d0180f737c26c23f57848cbc6a5a636a85c4bd6203
ssdeep: 12288:NWBm+95nHfFHmgewFx5vMiL4yaCM1kfgjdkA:NWBz95ndGgfx5vMAF7gjT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T105C4E05577928133E19701330E6BCAB659297C764B2A64CB63A4F33D2E317D1EB3530A
sha3_384: adf8ed481f04ff0f948a3028e68b7617094f066a4c1dd3e012213575303896e993fd79d5f3dd0e2d8621692fd0900e49
ep_bytes: e8d9650000e989feffff8bff558bec5d
timestamp: 2009-08-02 13:49:22

Version Info:

Comments: JPEG Image
FileDescription: JPEG Image
FileVersion: 6.1.7601.17514
ProductVersion: 6.1.7601.17514
Translation: 0x0409 0x04b0

Zusy.546156 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.5c98fe8833be466d
SkyhighBehavesLike.Win32.Generic.hc
ALYacGen:Variant.Zusy.546156
MalwarebytesWapomi.Virus.FileInfector.DDS
ZillyaBackdoor.Salgorea.Win32.69
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004e16831 )
K7GWTrojan ( 004e16831 )
ArcabitTrojan.Zusy.D8556C
VirITTrojan.Win32.Salgorea.A
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/TrojanDropper.Agent.RHG
APEXMalicious
McAfeeGenericRXLZ-NE!5C98FE8833BE
ClamAVWin.Malware.Bskd-9753126-0
KasperskyBackdoor.Win32.Salgorea.a
BitDefenderGen:Variant.Zusy.546156
NANO-AntivirusTrojan.Win32.Agent.djzunh
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
MicroWorld-eScanGen:Variant.Zusy.546156
AvastWin32:Agent-AYZG [Cryp]
TencentBackdoor.Win32.Salgorea.wa
TACHYONTrojan/W32.Salgorea.592325
EmsisoftGen:Variant.Zusy.546156 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen3
DrWebTrojan.Siggen6.24701
VIPREGen:Variant.Zusy.546156
Trapminemalicious.moderate.ml.score
SophosML/PE-A
IkarusTrojan-Dropper.Win32.Agent
JiangminTrojanDropper.Agent.brds
GoogleDetected
AviraTR/Crypt.XPACK.Gen3
Antiy-AVLTrojan[Backdoor]/Win32.Salgorea.gen
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Agent.QGO@57p1tw
MicrosoftTrojan:Win32/Cerber.MPI!MTB
ZoneAlarmBackdoor.Win32.Salgorea.a
GDataWin32.Trojan.PSE.19PBA7A
VaristW32/Agent.IOO.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R641912
BitDefenderThetaGen:NN.ZexaF.36804.K42@aSYpQ8ji
MAXmalware (ai score=80)
VBA32Backdoor.Salgorea
Cylanceunsafe
PandaTrj/Genetic.gen
RisingBackdoor.[OceanLotus]Salgorea!1.C3DC (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.12252991.susgen
FortinetW32/Agent.AYZG!tr
AVGWin32:Agent-AYZG [Cryp]
DeepInstinctMALICIOUS
alibabacloudTrojan[dropper]:Win/Salgorea

How to remove Zusy.546156?

Zusy.546156 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment