Trojan

Trojan:Win32/Zusy.GJN!MTB removal guide

Malware Removal

The Trojan:Win32/Zusy.GJN!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zusy.GJN!MTB virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Zusy.GJN!MTB?


File Info:

name: 5CBFF5224925DD8D14F5.mlw
path: /opt/CAPEv2/storage/binaries/e0afddc1969b116ae666f7d38fde9529a51846d950244e64914c41fea67b473f
crc32: 205D5497
md5: 5cbff5224925dd8d14f5c5c1841ab8f7
sha1: a0da8adde660ed8e232aa9873c36e970cfde6bf6
sha256: e0afddc1969b116ae666f7d38fde9529a51846d950244e64914c41fea67b473f
sha512: 9d3924ea7179ccf0f30504f7c00229df28303116893ea3944410e04b37eeebcd765b2ffd2a6dff68fb644049833d85e7ea6b7ca9ef9020217f6d4443f6bfa3f9
ssdeep: 768:ZTZ0BFt9VpT/beefzdB6NN46Ag6BqJGNEwfk/:ZKhBi4dB4q2JGu6k/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10A238F0278A0C433D84699B05875C5929E7FBF521FE1C08B7BAD12AE9F717C2573A30A
sha3_384: 61325ebfc6c2ed570a3c2579e08c1fbb6583ecb06444945c02b99f40d9f5b2aaeed52ce7ea41da22dcb62ceb4beedede
ep_bytes: e841150000e979feffff8bff558bc458
timestamp: 2012-03-15 11:39:12

Version Info:

0: [No Data]

Trojan:Win32/Zusy.GJN!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Convagent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.100475
CAT-QuickHealTrojan.GenericPMF.S30142465
McAfeeGenericRXVY-UB!5CBFF5224925
MalwarebytesMalware.Heuristic.1001
ZillyaTrojan.Convagent.Win32.22173
SangforTrojan.Win32.Wacatac.Vgwk
K7AntiVirusTrojan ( 005a81c81 )
AlibabaTrojan:Win32/Generic.05fc69a5
K7GWTrojan ( 005a81c81 )
CyrenW32/Zusy.QI.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.RopProof.A suspicious
BitDefenderTrojan.GenericKDZ.100475
AvastWin32:Evo-gen [Trj]
TencentPacked.Win32.Agent.kkh
EmsisoftTrojan.GenericKDZ.100475 (B)
F-SecureTrojan.TR/Agent_AGen.kapht
VIPRETrojan.GenericKDZ.100475
TrendMicroTROJ_GEN.R002C0PEM23
McAfee-GW-EditionBehavesLike.Win32.Generic.ph
FireEyeTrojan.GenericKDZ.100475
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.10G7SFC
AviraTR/Agent_AGen.kapht
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Generic.D1887B
MicrosoftTrojan:Win32/Zusy.GJN!MTB
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R577381
VBA32Trojan.Packed
ALYacTrojan.GenericKDZ.100475
MAXmalware (ai score=82)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0PEM23
RisingTrojan.Generic@AI.100 (RDML:nJRbYfOSFGF91hBZg10NjQ)
IkarusTrojan.Win32.Agent
FortinetW32/Wacatac.B!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Zusy.GJN!MTB?

Trojan:Win32/Zusy.GJN!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment