Malware

About “Buzy.2438” infection

Malware Removal

The Buzy.2438 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Buzy.2438 virus can do?

  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Buzy.2438?


File Info:

name: 6E1177FFD782B44A1E36.mlw
path: /opt/CAPEv2/storage/binaries/a1c70624a00a8bcb6c43b3c96421b2eaf4098e1aba2542b3410c519ba6a64702
crc32: 0DD08750
md5: 6e1177ffd782b44a1e36432440f30c49
sha1: 06f3e20810c1342f2334e1204142fab0f078567d
sha256: a1c70624a00a8bcb6c43b3c96421b2eaf4098e1aba2542b3410c519ba6a64702
sha512: 579b6bd0a7a340c8a612efbe4225317e2299e1c467ca9a9cdc2120685516c0daff80b01f1574ff249777c4fe0bd68fff7eb3f1badd155a7097a67b1dbcc00818
ssdeep: 6144:aky8bFI00UKwOaFcndaNWL2Iwi048L4F1em8t39ynFCSEM/9MdqpwamDpKK:Ta0tOaF2JLpR8L6eminSF9hGX8K
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E574022377F1D8B9C16255724D813AA582FAE7700A24CE036FD40A05BF39651FB2E2DB
sha3_384: 53102fcbcd5658cf7a959dfc67c6baf640a5b31fbbe04602fe9b0396d5dcf59e52aac572eff43385e4ecb8b7ed9e24f9
ep_bytes: 558bec6aff68f04c410068e029410064
timestamp: 2010-10-28 08:04:12

Version Info:

CompanyName: Oleg N. Scherbakov
FileDescription: 7z Setup SFX (x86)
FileVersion: 1.4.0.1912
InternalName: 7ZSfxMod
LegalCopyright: Copyright © 2005-2010 Oleg N. Scherbakov
OriginalFilename: 7ZSfxMod_x86.exe
PrivateBuild: October 22, 2010
ProductName: 7-Zip SFX
ProductVersion: 1.4.0.1912
Translation: 0x0000 0x04b0

Buzy.2438 also known as:

LionicTrojan.Win32.Chifrax.4!c
MicroWorld-eScanGen:Variant.Buzy.2438
FireEyeGen:Variant.Buzy.2438
ALYacGen:Variant.Buzy.2438
CylanceUnsafe
SangforTrojan.Win32.Chifrax.clm
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Chifrax.63473692
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.fd782b
BitDefenderThetaGen:NN.ZexaF.34742.vq3@ai0QrPmk
VirITTrojan.Win32.Generic.CNPM
Elasticmalicious (moderate confidence)
APEXMalicious
ClamAVWin.Downloader.130900-1
KasperskyTrojan.Win32.Chifrax.clm
BitDefenderGen:Variant.Buzy.2438
NANO-AntivirusTrojan.Win32.Renos.hbsym
AvastWin32:Renos-XM [Drp]
Ad-AwareGen:Variant.Buzy.2438
EmsisoftGen:Variant.Buzy.2438 (B)
ComodoMalware@#22wf11gj8ltgw
ZillyaDownloader.CodecPack.Win32.8442
TrendMicroTROJ_GEN.R002C0OFK22
McAfee-GW-EditionMultiDropper-UC
SophosMal/Generic-S
AviraTR/Dldr.Renos.MK
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Buzy.D986
ViRobotTrojan.Win32.A.Chifrax.323114
ZoneAlarmTrojan.Win32.Chifrax.clm
GDataGen:Variant.Buzy.2438
CynetMalicious (score: 99)
AhnLab-V3Downloader/Win32.CodecPack.C52875
McAfeeMultiDropper-UC
MAXmalware (ai score=86)
VBA32Trojan.Chifrax
TrendMicro-HouseCallTROJ_GEN.R002C0OFK22
RisingTrojan.Chifrax!8.309 (CLOUD)
YandexTrojan.DL.Renos!+n6CQFlreiw
IkarusPUA.7zip
FortinetW32/Generic.AC.233283!tr
AVGWin32:Renos-XM [Drp]
PandaGeneric Malware

How to remove Buzy.2438?

Buzy.2438 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment