Home Malware Programs Trojans Win-Trojan/Buzus.98304.X

Win-Trojan/Buzus.98304.X

Posted: October 30, 2009

Win-Trojan/Buzus.98304.X is a backdoor Trojan with widely-varying capabilities depending on which version infects your PC. Most Win-Trojan/Buzus.98304.X Trojans infect PCs by being bundled with cracks and other illegal security program that's widely distributed through torrents and other downloading services. Win-Trojan/Buzus.98304.X may attack your firewall, install keyloggers and other threats without your knowledge or consent, modify original system files, send data to or request data from malicious websites or use advanced SQL injection techniques. Any one of these attacks poses a sufficiently serious threat to your PC, which should make deleting Win-Trojan/Buzus.98304.X with an anti-malware program a top priority.

Blocking Win-Trojan/Buzus.98304.X's Initial Attacks

Win-Trojan/Buzus.98304.X is a relatively recent threat as of May 2011; you should strongly consider keeping both your security programs and browsers updated to protect yourself from Win-Trojan/Buzus.98304.X attacks. Win-Trojan/Buzus.98304.X is also notable for being Croatian in origin, which makes it appropriate to keep your defenses up whenever you're interacting with file sources from Croatia.

Win-Trojan/Buzus.98304.X is usually installed by accident, after you've installed a crack or other illegal security tool that's widely distributed through underground channels. Although Win-Trojan/Buzus.98304.X, like many Trojans, may show little to no signs of being active, Win-Trojan/Buzus.98304.X can run as a concealed memory process without requiring your permission to launch itself.

Since all known variants of Win-Trojan/Buzus.98304.X use standard startup Registry entry tactics to launch themselves, you should use Safe Mode, a CD-based boot, or a secondary operating system to insure that Win-Trojan/Buzus.98304.X isn't running. Attempting to close Win-Trojan/Buzus.98304.X manually or to delete Win-Trojan/Buzus.98304.X's files will rarely result in the successful removal of a full-blown Win-Trojan/Buzus.98304.X infection.

The Varied Implements of Security Disruption at Win-Trojan/Buzus.98304.X's Disposal

Although all known versions of Win-Trojan/Buzus.98304.X share a common startup technique, other Win-Trojan/Buzus.98304.X-related problems can vary widely. Depending on the type of Win-Trojan/Buzus.98304.X infection, you may experience any or all of the following:

  • Win-Trojan/Buzus.98304.X may download or upload files without your permission. This may be accomplished by direct attacks on your firewall that make your PC more vulnerable to other attacks. Alternately, Win-Trojan/Buzus.98304.X may use Background Intelligent Transfer Service (also known by the BIT acronym) exploits or other abuses to download files without interfering with your firewall directly.
  • Win-Trojan/Buzus.98304.X may modify native system files besides the Windows Registry to enable Win-Trojan/Buzus.98304.X's other attacks or to avoid being deleted.
  • Win-Trojan/Buzus.98304.X may record individual keystrokes from your keyboard. This keylogging is typically done to steal passwords and other private information which is sent to remote criminals.
  • Win-Trojan/Buzus.98304.X may create many different types of Mutex files to keep track of Win-Trojan/Buzus.98304.X's access to your system, and to prevent other infections from interfering with Win-Trojan/Buzus.98304.X's attacks.
  • Win-Trojan/Buzus.98304.X may use Havij and other SQL injection tools to gather personal data or alter private settings.
  • Win-Trojan/Buzus.98304.X may install other threats on your PC that can cause a wide range of other problems that aren't limited to any of the attacks described above.

Along with all of these attacks, Win-Trojan/Buzus.98304.X may also create a wide range of executable files in varied locations, register .dll files and generally create sophisticated components that are difficult to remove without assistance. It's strongly suggested that you delete Win-Trojan/Buzus.98304.X by using an anti-malware program to scan your entire PC for all possible components of a Win-Trojan/Buzus.98304.X infection.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %CommonStartMenu%\IMAIG.exe
    2 %ProgramFiles%\system\amg.exe
    3 C:\Extracted\DzGmax_D.rar
    4 C:\Extracted\IMAIG.exe
Loading...