Malware

Zusy.102077 removal tips

Malware Removal

The Zusy.102077 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zusy.102077 virus can do?

  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • CAPE detected the njRat malware family
  • Anomalous binary characteristics

How to determine Zusy.102077?


File Info:

name: BF36CC77448259EBA001.mlw
path: /opt/CAPEv2/storage/binaries/4311bc7ef0da6b61d4d35542fecead30ca19dfc4534d4035beb0094df8748dac
crc32: FF76AA8D
md5: bf36cc77448259eba001493dbc7f14f9
sha1: 5273791df557272b09bd8e2fa67d3092ad2042dd
sha256: 4311bc7ef0da6b61d4d35542fecead30ca19dfc4534d4035beb0094df8748dac
sha512: d6775870d8ef7b5f780922d3161d57edfd8e6ece1f06333a829d90739a8af2a520c87b414bc4c92b3c5f07bb1e15c2ebf10ba6f21dba5857c9d39e3c3ea8ba34
ssdeep: 384:S8aSyS9gB3Y1KIay2X8cLZI6XgxsGJVPpmRvR6JZlbw8hqIusZzZc6E:F589tXvRpcnuz3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E9B22A4E3FA98856C5AC17748AA5965003B491470413EE3FCDC564CBAFB3ADA1D4CAF8
sha3_384: 8d2213340ec2cf26743e3fa97be4068981d45b1b94e5da14dfce4867b766a2e0ccf224b21c2b38167d1ee1caacd5d1b2
timestamp: 2018-01-25 20:25:42

Version Info:

0: [No Data]

Zusy.102077 also known as:

BkavW32.AIDetectNet.01
DrWebBackDoor.Bladabindi.13678
MicroWorld-eScanGen:Variant.Zusy.102077
FireEyeGeneric.mg.bf36cc77448259eb
CAT-QuickHealTrojan.Generic.TRFH5
McAfeeTrojan-FLFD!BF36CC774482
MalwarebytesBladabindi.Backdoor.Njrat.DDS
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.744825
VirITBackdoor.Win32.Generic.AWM
CyrenW32/MSIL_Bladabindi.DJ.gen!Eldorado
SymantecBackdoor.Ratenjay
ElasticWindows.Trojan.Njrat
ESET-NOD32a variant of MSIL/Bladabindi.AS
APEXMalicious
TrendMicro-HouseCallTROJ_BLADABINDI.SMB3
ClamAVWin.Packed.Generic-9795615-0
KasperskyBackdoor.MSIL.Agent.igo
BitDefenderGen:Variant.Zusy.102077
NANO-AntivirusTrojan.Win32.Disfa.dtznyx
AvastMSIL:Agent-DRD [Trj]
TencentTrojan.Msil.Bladabindi.za
Ad-AwareGen:Variant.Zusy.102077
EmsisoftTrojan.Bladabindi (A)
ComodoHeur.Corrupt.PE@1z141z3
BaiduMSIL.Backdoor.Bladabindi.a
VIPREGen:Variant.Zusy.102077
TrendMicroTROJ_BLADABINDI.SMB3
McAfee-GW-EditionBehavesLike.Win32.Trojan.mm
Trapminemalicious.high.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataMSIL.Backdoor.Bladabindi.AV
JiangminTrojanDropper.Autoit.dce
GoogleDetected
AviraTR/Dropper.Gen7
MAXmalware (ai score=87)
ZoneAlarmBackdoor.MSIL.Agent.igo
MicrosoftBackdoor:MSIL/Bladabindi
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Bladabindi.R91438
Acronissuspicious
ALYacGen:Variant.Zusy.102077
RisingBackdoor.njRAT!1.9E49 (CLASSIC)
IkarusTrojan.MSIL.Bladabindi
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.7A12!tr
AVGMSIL:Agent-DRD [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Zusy.102077?

Zusy.102077 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment