Trojan

Trojan:Win32/Zusy.RD!MTB removal

Malware Removal

The Trojan:Win32/Zusy.RD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zusy.RD!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Zusy.RD!MTB?


File Info:

name: 3AAE10D92594F2E9F642.mlw
path: /opt/CAPEv2/storage/binaries/b6f544a9ad69419227405faadf67f84825aecf2348480b0fc9c8a247f634433d
crc32: EB1FAD8A
md5: 3aae10d92594f2e9f6427b5be456d6be
sha1: 86248721e3dcec2be483316ad34a844d23df4273
sha256: b6f544a9ad69419227405faadf67f84825aecf2348480b0fc9c8a247f634433d
sha512: c007f962c3fd3882d57433588eee5a0f16998d09ae5437ad185086d716c81958c875a1020a2895e21734dbb95500567cc02fed3b54d5db676f86d64a39d462f2
ssdeep: 98304:4Qi6kojkI00DzNpAkQ9FGunmtrl8z9rNSFNysSzr4YpvY4Wj9arrQ:ffb7jzNpCznmn8z9rNEdSgYZbWg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T191667A3D8C5EF66EEABAE233E4547A0DF0A2176E7246E84D94E346C4887B25770C431D
sha3_384: c1236fdbec1158b01abd84621f650da43f191ab9833501afbd432f3bdc8a744872b01ae02cf9b57cfa751eb53618aa13
ep_bytes: 558bec83e4f881ec1808000068100800
timestamp: 2019-09-25 23:39:00

Version Info:

0: [No Data]

Trojan:Win32/Zusy.RD!MTB also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.530573
FireEyeGeneric.mg.3aae10d92594f2e9
SkyhighGenericRXWL-YM!3AAE10D92594
McAfeeGenericRXWL-YM!3AAE10D92594
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Zusy.530573
Cybereasonmalicious.1e3dce
ArcabitTrojan.Zusy.D8188D
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.HVJN
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Zusy.530573
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Evo-gen [Trj]
SophosMal/Generic-S
EmsisoftGen:Variant.Zusy.530573 (B)
SentinelOneStatic AI – Malicious PE
GoogleDetected
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/Zusy.RD!MTB
GDataWin32.Trojan.PSE.11MOEJX
VaristW32/Graftor.B.gen!Eldorado
AhnLab-V3Trojan/Win.Generic.R627168
ALYacGen:Variant.Zusy.530573
Cylanceunsafe
RisingTrojan.Kryptik!8.8 (TFE:4:EJUJJwBub2R)
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HVJN!tr
AVGWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Trojan:Win32/Zusy.RD!MTB?

Trojan:Win32/Zusy.RD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment