Trojan

Trojan:Win32/Zusy.CREL!MTB removal guide

Malware Removal

The Trojan:Win32/Zusy.CREL!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zusy.CREL!MTB virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Trojan:Win32/Zusy.CREL!MTB?


File Info:

name: E440D159D113DB48D2FB.mlw
path: /opt/CAPEv2/storage/binaries/da0df6835d90319d8fff415d859eaf31cd259c02af573ac11dd4eeb0c3f340c7
crc32: D14FD619
md5: e440d159d113db48d2fb5a9cbf5ef848
sha1: 843a81627e450811cc47b358389d31a8072e67aa
sha256: da0df6835d90319d8fff415d859eaf31cd259c02af573ac11dd4eeb0c3f340c7
sha512: 4fc9e065a895c75aef363ec5f961fccd015989b79e05e9848d3a11664bf9818e5cd7060c33ab0133b77336ffb37dadc1c8c24ed54ce7f3e318459f4a265efd49
ssdeep: 6144:ao+fyse8bRrMwwl29PvIMtuukYmiZo5E2wgCCicsKBxju/NMYtj2f1aIrtRoCVbO:Q9ZRrf6YxHZPoC9tjk1NXom
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14DD45A52EA84A0A8E4F536FF45B640E602D78EC86366D2DF59BC7561FFF42912C3024B
sha3_384: 75b329a183b7999cd6d2b4204a96e314bcc28c49a263af90f485f0838cfa8d611eb50ba343aee5e6fcf0a18635cff7b3
ep_bytes: e8ee160000e9000000006a1468f81549
timestamp: 2023-05-09 12:15:26

Version Info:

0: [No Data]

Trojan:Win32/Zusy.CREL!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Zusy.4!c
MicroWorld-eScanGen:Variant.Zusy.466363
FireEyeGeneric.mg.e440d159d113db48
McAfeeGenericRXAA-AA!E440D159D113
MalwarebytesCrypt.Trojan.Malicious.DDS
SangforTrojan.Win32.Kryptik.Vqg8
K7AntiVirusTrojan ( 005a58651 )
AlibabaTrojan:Win32/Kryptik.61732168
K7GWTrojan ( 005a58651 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36250.KqX@aqbfdpm
VirITTrojan.Win32.Genus.QNT
CyrenW32/ABRisk.BLFX-4062
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.HTMY
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Zusy.466363
NANO-AntivirusTrojan.Win32.Kryptik.jwgffi
AvastWin32:TrojanX-gen [Trj]
TencentWin32.Trojan.Crypt.Fmnw
EmsisoftGen:Variant.Zusy.466363 (B)
F-SecureTrojan.TR/Crypt.Agent.qnbdh
VIPREGen:Variant.Zusy.466363
TrendMicroTROJ_GEN.R002C0DEG23
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
GDataGen:Variant.Zusy.466363
AviraTR/Crypt.Agent.qnbdh
Antiy-AVLGrayWare/Win32.Wacapew
ArcabitTrojan.Zusy.D71DBB
ViRobotTrojan.Win.Z.Zusy.601606.A
MicrosoftTrojan:Win32/Zusy.CREL!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Zusy.C5426021
ALYacGen:Variant.Zusy.466363
MAXmalware (ai score=84)
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DEG23
RisingTrojan.Kryptik!8.8 (TFE:5:kV6zzGwT9TR)
YandexTrojan.Kryptik!APn/c6z+P7g
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.207657962.susgen
FortinetPossibleThreat.PALLAS.H
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Zusy.CREL!MTB?

Trojan:Win32/Zusy.CREL!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment