Home Malware Programs Trojans Trojan.Bukflash

Trojan.Bukflash

Posted: March 13, 2014

Threat Metric

Threat Level: 9/10
Infected PCs: 361
First Seen: March 13, 2014
Last Seen: April 12, 2023
OS(es) Affected: Windows


Trojan.Bukflash is a Trojan that may gain access to social media profiles on the targeted computer. Trojan.Bukflash is known to propagate by posting links on compromised social media accounts. These links reroute PC users to websites that state to host a Flash update. When executed, Trojan.Bukflash creates the potentially malicious file on the computer system. Trojan.Bukflash modifies the Windows Registry by creating the registry subkeys on the PC. Trojan.Bukflash also creates the registry entries. Trojan.Bukflash may then carry out the malicious actions such as gain access to the computer user's social media profile, photos and personal information, download and execute files, and aim to divert computer users to numerous suspicious websites.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ProgramFiles%\Flash\first.crx File name: %ProgramFiles%\Flash\first.crx
Mime Type: unknown/crx
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eloiobpkhmhigoanlnojhnacenlkjaad\"version" = "1.0.4"HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\eloiobpkhmhigoanlnojhnacenlkjaad\"version" = "1.0.4"HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eloiobpkhmhigoanlnojhnacenlkjaad\"path" = "%ProgramFiles%\Flash\first.crx"HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\eloiobpkhmhigoanlnojhnacenlkjaad\"path" = "%ProgramFiles%\Flash\first.crx"HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\eloiobpkhmhigoanlnojhnacenlkjaadHKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\eloiobpkhmhigoanlnojhnacenlkjaad
Loading...