Trojan

Trojan:Win32/Zusy.GXZ!MTB information

Malware Removal

The Trojan:Win32/Zusy.GXZ!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zusy.GXZ!MTB virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • The sample wrote data to the system hosts file.

How to determine Trojan:Win32/Zusy.GXZ!MTB?


File Info:

name: 83C56849F95C230464B1.mlw
path: /opt/CAPEv2/storage/binaries/08e95bddbfd72164a27921d9a0287bf3bf1c0150e891b0aefd45b791eb21c59a
crc32: F0AE5B9A
md5: 83c56849f95c230464b13309d25e17dd
sha1: bfd5298843497ac04a86c23d637bff44375251ae
sha256: 08e95bddbfd72164a27921d9a0287bf3bf1c0150e891b0aefd45b791eb21c59a
sha512: a2e1ba5114db8ed072d7a00199300643fe4624055b79f42c73781d9da841765ae9b0c0dc2a9fbf1ca5bdbea3977f1e5d5eec3a7605749ba0f73f5fb3a44e13a6
ssdeep: 1536:Ay2wpOqmXZ879wlQd0pBbgUuQF8uHBx7ghY4Mmw07:N2oIZ879wlQd0pyihFkdwo
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1EC63A713FF5DC675D08142F4E1AD9BA5926AE1228F9087D377C0562ABC644CBAC7CE0B
sha3_384: 5d79647ba57657e473ed47b334cbdc579feb002b8f762580282afc5ec64fe026645b85821231232c2df7a92163c7b655
ep_bytes: e8dd050000e974feffffc20000558bec
timestamp: 2024-04-23 15:42:08

Version Info:

0: [No Data]

Trojan:Win32/Zusy.GXZ!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.546369
FireEyeGeneric.mg.83c56849f95c2304
CAT-QuickHealTrojan.Zusy
Cylanceunsafe
SangforTrojan.Win32.Zusy.Vpfc
AlibabaTrojanSpy:Win32/Redcap.33772852
K7GWRiskware ( 00584baa1 )
K7AntiVirusRiskware ( 00584baa1 )
ArcabitTrojan.Zusy.D85641
SymantecML.Attribute.HighConfidence
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R011C0DE224
Paloaltogeneric.ml
BitDefenderGen:Variant.Zusy.546369
AvastWin32:TrojanX-gen [Trj]
EmsisoftGen:Variant.Zusy.546369 (B)
F-SecureTrojan.TR/Redcap.dnsin
DrWebTrojan.Hosts.51877
VIPREGen:Variant.Zusy.546369
TrendMicroTROJ_GEN.R011C0DE224
SophosMal/Generic-S
IkarusTrojan-Spy.Zbot
GoogleDetected
AviraTR/Redcap.dnsin
VaristW32/Blocker-based!Maximus
Antiy-AVLTrojan/Win32.Sabsik
MicrosoftTrojan:Win32/Zusy.GXZ!MTB
ViRobotTrojan.Win.Z.Zusy.73267
GDataWin32.Trojan.PSE.9EA4E1
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.R646426
ALYacGen:Variant.Zusy.546369
MAXmalware (ai score=81)
VBA32suspected of Trojan.Downloader.gen
MalwarebytesTrojan.AutoRun
PandaTrj/GdSda.A
RisingTrojan.Generic@AI.94 (RDML:ZPl6MpnL+8GMQUoa1kgg7w)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.242592547.susgen
FortinetPossibleThreat.PALLAS.H
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Zusy.GXZ!MTB?

Trojan:Win32/Zusy.GXZ!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment