Trojan

How to remove “Trojan:Win32/Zusy!MTB”?

Malware Removal

The Trojan:Win32/Zusy!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zusy!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Deletes executed files from disk

How to determine Trojan:Win32/Zusy!MTB?


File Info:

name: 668AAF538103A7C4068A.mlw
path: /opt/CAPEv2/storage/binaries/9b703af268fc7aa6e7330e247f3afe0f83c013e4dd81f0c380e09a309e1c200b
crc32: 1D204215
md5: 668aaf538103a7c4068abfdf06e331f2
sha1: 3c1c65b9c3e1343ea6ffe0925b750ec27a4b34eb
sha256: 9b703af268fc7aa6e7330e247f3afe0f83c013e4dd81f0c380e09a309e1c200b
sha512: 3cab60c41dd835333620e72d14ad8bf7524f819e0d3b753ef6c76b8c127bfea4a906d5a54dab3590572f9c48163cee9ca8b180d2c9b757e646cfd7ef79cfdd6f
ssdeep: 49152:SBuZrEUHoP/QIpwiJjnedH5T1V55DdN7POGj4:kkLInQIpbTeLH55lj4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BAB5E03FF268A53EC5AA1B3205B38210997BBA61781B8C1E47FC344DCF765601E3B656
sha3_384: cd48c8d2cfdbfeef528f347366d1d9dae7d709751153d1d2f249e64c3ee47b48fb45f1ce27f121033cb692d8fde848ae
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2022-04-14 16:10:23

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: gojeeoh31h Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: gojeeoh31h
ProductVersion: 157.221.17
Translation: 0x0000 0x04b0

Trojan:Win32/Zusy!MTB also known as:

MicroWorld-eScanTrojan.GenericKD.62237293
McAfeeArtemis!668AAF538103
CylanceUnsafe
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojan:Win32/DangerousSig.c5cdbee1
CrowdStrikewin/grayware_confidence_70% (D)
CyrenW32/Convagent.AH.gen!Eldorado
SymantecTrojan.Gen.MBT
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Kryptik.HQSW
Paloaltogeneric.ml
BitDefenderTrojan.GenericKD.62237293
AvastWin32:TrojanX-gen [Trj]
Ad-AwareTrojan.GenericKD.62237293
EmsisoftTrojan.GenericKD.62237293 (B)
VIPRETrojan.GenericKD.62237293
TrendMicroTROJ_GEN.R067C0DIP22
McAfee-GW-EditionArtemis!Trojan
FireEyeTrojan.GenericKD.62237293
GDataWin32.Trojan-Stealer.TinyNuke.NQIS6O
WebrootW32.Trojan.Emotet
GoogleDetected
AviraHEUR/AGEN.1251348
MAXmalware (ai score=88)
ArcabitTrojan.Generic.D3B5AA6D
MicrosoftTrojan:Win32/Zusy!MTB
AhnLab-V3Trojan/Win.Sabsik.C5242351
ALYacTrojan.GenericKD.62237293
MalwarebytesTrojan.Bundler
TrendMicro-HouseCallTROJ_GEN.R067C0DIP22
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/PossibleThreat
AVGWin32:TrojanX-gen [Trj]

How to remove Trojan:Win32/Zusy!MTB?

Trojan:Win32/Zusy!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment