Malware

Buzy.2282 (file analysis)

Malware Removal

The Buzy.2282 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Buzy.2282 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Code injection with CreateRemoteThread in a remote process
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process

How to determine Buzy.2282?


File Info:

name: E8FE98EAF9E66D40089A.mlw
path: /opt/CAPEv2/storage/binaries/f8d25670944746dbff71519f855732813bcf8e3cadebf323ebf95f1303d26cb9
crc32: 0373D8CD
md5: e8fe98eaf9e66d40089a919beb32867c
sha1: ca2350cd42ab1632fa00e6d0d470e62c496752ac
sha256: f8d25670944746dbff71519f855732813bcf8e3cadebf323ebf95f1303d26cb9
sha512: 281b8c7a48e90c360f740e06052503b28133631d85c68374d9bebbc0bd1267635a881e9eec2d68dd1183bbad77014a07daab92bee5ce4fac0d2e550d1ecd2d66
ssdeep: 6144:TYGa+szRMW7Sv+IOQKA7qNiIcwIiHwTqAaN9:zavRMW8+NiI5Ya
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E6141282B3D9E569D1A1DDB7E207E6D18B380997472A6CBECC71C0DBBC312D1C54B609
sha3_384: d0909d24cf519227711b4fcdfcfc0df4664c4615382e2dd1a6f1cb2b503d7d8bc8310e76e5c9ab9272435d491831f23a
ep_bytes: 60be000042008dbe0010feff5783cdff
timestamp: 2010-06-18 07:20:52

Version Info:

Translation: 0x0804 0x04b0
ProductName: Loader
FileVersion: 1.00
ProductVersion: 1.00
InternalName: Loader
OriginalFilename: Loader.exe

Buzy.2282 also known as:

LionicTrojan.Win32.VB.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.e8fe98eaf9e66d40
McAfeeGenericRXAA-AA!E8FE98EAF9E6
CylanceUnsafe
ZillyaTrojan.VB.Win32.45768
SangforTrojan.Win32.Buzy.2282
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojan:Win32/Meredrop.640911c9
K7GWNetWorm ( 700000151 )
K7AntiVirusNetWorm ( 700000151 )
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/VB.QBV
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Buzy-6840162-0
KasperskyTrojan.Win32.VB.ahjt
BitDefenderGen:Variant.Buzy.2282
NANO-AntivirusTrojan.Win32.VB.cvyhp
MicroWorld-eScanGen:Variant.Buzy.2282
AvastFileRepMalware
TencentMalware.Win32.Gencirc.10c29445
Ad-AwareGen:Variant.Buzy.2282
SophosMal/Generic-S
ComodoTrojWare.Win32.Injector.ZVDA@4ydyx1
DrWebTrojan.Inject.52556
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
EmsisoftGen:Variant.Buzy.2282 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Buzy.2282
JiangminTrojan/VB.apyt
WebrootW32.Malware.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.VB
ArcabitTrojan.Buzy.D8EA
ViRobotTrojan.Win32.A.VB.198144[UPX]
ZoneAlarmTrojan.Win32.VB.ahjt
MicrosoftPWS:Win32/Zbot!ml
TACHYONTrojan/W32.VB-Agent.311296.BG
AhnLab-V3Trojan/Win32.Sasfis.R1155
ALYacGen:Variant.Buzy.2282
MAXmalware (ai score=100)
VBA32Trojan.VBRA.01174
MalwarebytesMalware.AI.2509428348
RisingDropper.Generic!8.35E (CLOUD)
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.1419055.susgen
FortinetW32/VB.LYK!tr.bdr
AVGFileRepMalware
Cybereasonmalicious.af9e66
PandaGeneric Malware

How to remove Buzy.2282?

Buzy.2282 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment