Home Malware Programs Trojans Trojan.Buzus

Trojan.Buzus

Posted: February 15, 2008

Threat Metric

Ranking: 16,637
Threat Level: 9/10
Infected PCs: 10,652
First Seen: July 24, 2009
Last Seen: August 30, 2023
OS(es) Affected: Windows

Trojan.Buzus is a Trojan infection designed to steal various personal information such as credit card and banking account numbers. Trojan.Buzus also has the ability to compromise the security settings of your system leaving your computer vulnerable to outside attacks or remote users. Trojan.Buzus has been proven to be difficult to manually remove from any infected machine.

Aliases

SHeur4.QZD [AVG]Backdoor.Gen3 [Ikarus]TR/Crypt.ZPACK.Gen2 [AntiVir]Mal/Autorun-AS [Sophos]Trojan.Generic.7235059 [BitDefender]Trojan.Win32.Jorik.IRCbot.hmp [Kaspersky]a variant of Win32/Kryptik.AAZY [NOD32]Artemis!2D9C4AD32F50 [McAfee]Worm/Generic2.BEEF [AVG]W32/Jorik_IRCbot.CEE!tr [Fortinet]Backdoor/Win32.IRCBot.gen [Antiy-AVL]TR/Crypt.ZPACK.Gen [AntiVir]Worm.Generic.358674 [BitDefender]Trojan.Win32.Jorik.IRCbot.fah [Kaspersky]Win32.TRCrypt.ZPACK [eSafe]
More aliases (1420)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



C:\Users\<username>\AppData\Roaming\Uninstall.exe File name: Uninstall.exe
Size: 135.27 KB (135276 bytes)
MD5: 9c1abef6be60b1d8572681c9475b9077
Detection count: 6,153
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\Uninstall.exe
Group: Malware file
Last Updated: May 14, 2022
%APPDATA%\ohydy.exe File name: ohydy.exe
Size: 111.61 KB (111616 bytes)
MD5: 474d68a1647482c7772e96bc4dff0cdb
Detection count: 773
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: September 15, 2010
%WINDIR%\system\iexplorer.exe File name: iexplorer.exe
Size: 52.39 KB (52399 bytes)
MD5: 771a2e39198c5fec9b8481d5abf263b6
Detection count: 84
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system
Group: Malware file
Last Updated: October 6, 2010
cndrive32.exe File name: cndrive32.exe
Size: 78.33 KB (78336 bytes)
MD5: 3cba73a7092605d59b1d4aeef2f6db11
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: August 12, 2010
file.exe File name: file.exe
Size: 475.64 KB (475648 bytes)
MD5: baf89a5874bed991c8572cf79df3e1a7
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 2, 2017
%APPDATA%\SystemProc\lsass.exe File name: lsass.exe
Size: 202.24 KB (202240 bytes)
MD5: 591e67063e00e1b7c41663dd3c01ac44
Detection count: 64
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\SystemProc
Group: Malware file
Last Updated: October 26, 2010
%WINDIR%\aadrive32.exe File name: aadrive32.exe
Size: 114.68 KB (114688 bytes)
MD5: 8b050449f58a199f712963bea0713336
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: November 21, 2011
%WINDIR%\cndrive32.exe File name: cndrive32.exe
Size: 66.04 KB (66048 bytes)
MD5: 20110b93b7f87c8a5fcf0fe55a2ba068
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: December 7, 2010
C:\Users\<username>\AppData\Roaming\1919.tmp File name: 1919.tmp
Size: 86.01 KB (86016 bytes)
MD5: 4daa0dccda1d0e9d80632021d18da11d
Detection count: 21
File type: Temporary File
Mime Type: unknown/tmp
Path: C:\Users\<username>\AppData\Roaming\1919.tmp
Group: Malware file
Last Updated: August 27, 2022
C:\Users\<username>\AppData\Roaming\1EAD.tmp File name: 1EAD.tmp
Size: 118.78 KB (118784 bytes)
MD5: be1938b65c7a608056458fcf3e87a086
Detection count: 19
File type: Temporary File
Mime Type: unknown/tmp
Path: C:\Users\<username>\AppData\Roaming\1EAD.tmp
Group: Malware file
Last Updated: January 20, 2022
C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1455\fredg.exe File name: fredg.exe
Size: 45.05 KB (45056 bytes)
MD5: da4d85481494b94d4d0fa5f98a064795
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: C:\RECYCLER\S-1-5-21-0243556031-888888379-781863308-1455
Group: Malware file
Last Updated: October 28, 2010
%PUBLIC%\winsvcn.exe File name: winsvcn.exe
Size: 81.4 KB (81408 bytes)
MD5: 5ac73655e80160556f0c672c3c8a3a3e
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %PUBLIC%
Group: Malware file
Last Updated: November 2, 2010
%WINDIR%\system32\config\svchost.exe    File name: svchost.exe   
Size: 315.82 KB (315821 bytes)
MD5: d4a4a090abada68f954785d32c02d194
Detection count: 14
Mime Type: unknown/exe   
Path: %WINDIR%\system32\config
Group: Malware file
Last Updated: October 28, 2010
C:\Users\<username>\AppData\Roaming\1834.tmp File name: 1834.tmp
Size: 86.01 KB (86016 bytes)
MD5: ce335ecc5b36b8faf8d1d301b9d550a4
Detection count: 12
File type: Temporary File
Mime Type: unknown/tmp
Path: C:\Users\<username>\AppData\Roaming\1834.tmp
Group: Malware file
Last Updated: August 27, 2022
C:\Users\<username>\AppData\Roaming\47AD.tmp File name: 47AD.tmp
Size: 86.01 KB (86016 bytes)
MD5: e3236f731a60a4fa2ab6d51b41280bad
Detection count: 12
File type: Temporary File
Mime Type: unknown/tmp
Path: C:\Users\<username>\AppData\Roaming\47AD.tmp
Group: Malware file
Last Updated: August 27, 2022
C:\RECYCLER\S-1-5-21-6136269465-0102912693-024135967-8091\rundll32.exe File name: rundll32.exe
Size: 119.8 KB (119808 bytes)
MD5: 3707d63b76c646a53b82f058b0fb05eb
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: C:\RECYCLER\S-1-5-21-6136269465-0102912693-024135967-8091
Group: Malware file
Last Updated: November 2, 2010
%APPDATA%\Microsoft\svchost.exe File name: svchost.exe
Size: 217.08 KB (217088 bytes)
MD5: 385b3a4acfe96309252ad9c5229610d3
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft
Group: Malware file
Last Updated: November 3, 2010
%WINDIR%\system32\msvmiode.exe File name: msvmiode.exe
Size: 131.07 KB (131072 bytes)
MD5: e5dcb2d8939cce433abd79688fb30527
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: December 7, 2010
%WINDIR%\aadrive32.exe File name: aadrive32.exe
Size: 49.15 KB (49152 bytes)
MD5: 2d9c4ad32f509c44cd31e4f63e827cc7
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: March 6, 2012
C:\Users\<username>\AppData\Roaming\D941.tmp File name: D941.tmp
Size: 86.01 KB (86016 bytes)
MD5: 8fd13283ab7be9feda213f1046c894a1
Detection count: 5
File type: Temporary File
Mime Type: unknown/tmp
Path: C:\Users\<username>\AppData\Roaming\D941.tmp
Group: Malware file
Last Updated: August 27, 2022

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%WINDIR%\winsvc32.exe

Related Posts

Loading...