Trojan

Trojan.Win32.Buzus.mqui information

Malware Removal

The Trojan.Win32.Buzus.mqui is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Buzus.mqui virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Operates on local firewall’s policies and settings
  • Anomalous binary characteristics

How to determine Trojan.Win32.Buzus.mqui?


File Info:

crc32: BCBEEFF0
md5: fb1ef371d60d3c9c4022268a386b4e59
name: FB1EF371D60D3C9C4022268A386B4E59.mlw
sha1: 1196b5fffcf373f998ac1123fa55da8646fa7f75
sha256: 1a1fa7da36a6985919a5d1a2030a96a5675656295ce53c9828802d7a3f1f0bad
sha512: 7145d6f876efc3cf3edd1ac479324e38ce53bce47cfbc3c14e53faea29a0d233da3adde1cb8a322a3fcfff0ca1797c4314fb722099bbf46968df5351fe839254
ssdeep: 6144:Lqc8vq/8H/WVyVOROP9BFh7kbtXGQoRgQECW:Lx9o3g8QEHW
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan.Win32.Buzus.mqui also known as:

LionicTrojan.Win32.Buzus.4!c
Elasticmalicious (high confidence)
DrWebTrojan.MulDrop4.11302
CynetMalicious (score: 100)
ALYacGen:Heur.Zygug.6
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojan:Win32/Buzus.f0ec0033
Cybereasonmalicious.1d60d3
CyrenW32/Hamweq.D.gen!Eldorado
SymantecTrojan.Shylock
ESET-NOD32a variant of Win32/Injector.YPZ
APEXMalicious
AvastWin32:Cryptor
KasperskyTrojan.Win32.Buzus.mqui
BitDefenderGen:Heur.Zygug.6
NANO-AntivirusTrojan.Win32.Buzus.bbxhjo
ViRobotTrojan.Win32.A.Buzus.210432.E
MicroWorld-eScanGen:Heur.Zygug.6
TencentWin32.Trojan.Buzus.Ecty
Ad-AwareGen:Heur.Zygug.6
SophosML/PE-A + Mal/EncPk-AHQ
ComodoTrojWare.Win32.PWS.ZBot.AAA@4sq88d
BitDefenderThetaGen:NN.ZexaF.34236.mGW@auCsERai
VIPRETrojan.Win32.Encpk.ahq (v)
TrendMicroTROJ_RANSOM.SMWX
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.dc
FireEyeGeneric.mg.fb1ef371d60d3c9c
EmsisoftGen:Heur.Zygug.6 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Buzus.bjho
WebrootTrojan.Dropper.Gen
AviraTR/Dropper.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.1F2BF7
MicrosoftWorm:Win32/Dorkbot
GDataGen:Heur.Zygug.6
AhnLab-V3Trojan/Win32.Zbot.R44919
McAfeePWS-Zbot.gen.apx
MAXmalware (ai score=100)
VBA32Worm.Dorkbot.1312
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_RANSOM.SMWX
RisingTrojan.Generic@ML.94 (RDML:4n4CKfLfhnN55OC/3ghz6g)
IkarusTrojan.Win32.Buzus
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Ransom.AAX!tr
AVGWin32:Cryptor
Paloaltogeneric.ml

How to remove Trojan.Win32.Buzus.mqui?

Trojan.Win32.Buzus.mqui removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment