Trojan

Trojan:Win32/Zusy.DV!MTB removal tips

Malware Removal

The Trojan:Win32/Zusy.DV!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zusy.DV!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • Authenticode signature is invalid

How to determine Trojan:Win32/Zusy.DV!MTB?


File Info:

name: 4F1897CFB6041224E59B.mlw
path: /opt/CAPEv2/storage/binaries/5281e175174a06cdf3155183affa4e33260108d2cff496db9aece67031bbd79e
crc32: A781FDCA
md5: 4f1897cfb6041224e59b44d070de72d6
sha1: 87b3174340ae5fcf527bda52a9565cfa6bdfe70d
sha256: 5281e175174a06cdf3155183affa4e33260108d2cff496db9aece67031bbd79e
sha512: 3495370176481cc6a81510238268b68ea993e2b6588d4c21b537ebc5043cd4a6378bb1dd72d6947124866e9678a1403222446b6b450187e0a4eccc8a67ba47cf
ssdeep: 768:Ql/BNZ04Zu+75kKMXdaPAPqTRn7RfRGgxjbPr:8XZ04I+75vocOqTRn7RfRx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16DF25A939E0484F3F3CE267540A02E6FC7ED9D352671AC0BD3A47D9AA9BB0D0D724245
sha3_384: fcbc321011c97e72104d1fa985f17d9eebb14517718f9f55e76146f0bac4e2885a3bcc77fd16d4a78d69fff2e68f8cb1
ep_bytes: 8d740601381e75bf6aff33f646568d45
timestamp: 2013-11-25 12:49:14

Version Info:

0: [No Data]

Trojan:Win32/Zusy.DV!MTB also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.467914
SkyhighBehavesLike.Win32.Generic.nz
McAfeeGenericRXVS-FX!4F1897CFB604
MalwarebytesMachineLearning/Anomalous.100%
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Zusy.D723CA
BitDefenderThetaAI:Packer.C3749FC31E
SymantecW32.Wapomi.C!inf
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Agent_AGen.AWZ
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Bdld-9770176-0
KasperskyUDS:Trojan.Win32.GenericML.xnet
BitDefenderGen:Variant.Zusy.467914
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
AvastWin32:TrojanX-gen [Trj]
EmsisoftGen:Variant.Zusy.467914 (B)
F-SecureMalware.W32/Jadtre.D
VIPREGen:Variant.Zusy.467914
TrendMicroTROJ_GEN.R03BC0CAK24
SophosML/PE-A
IkarusTrojan-Downloader.Win32.Small
VaristW32/Jadtre.B.gen!Eldorado
AviraW32/Jadtre.D
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Zusy.DV!MTB
ZoneAlarmUDS:Trojan.Win32.GenericML.xnet
GDataGen:Variant.Zusy.467914
GoogleDetected
AhnLab-V3Trojan/Win32.Wacatac.C4089906
Acronissuspicious
ALYacGen:Variant.Zusy.467914
Cylanceunsafe
PandaGeneric Suspicious
TrendMicro-HouseCallTROJ_GEN.R03BC0CAK24
RisingTrojan.Agent!1.9CF8 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.AWZ!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.340ae5
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Zusy.DV!MTB?

Trojan:Win32/Zusy.DV!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment