Trojan

Trojan.Win32.Buzus.mwwv (file analysis)

Malware Removal

The Trojan.Win32.Buzus.mwwv is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Buzus.mwwv virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)

How to determine Trojan.Win32.Buzus.mwwv?


File Info:

name: 10090FE8DF4D35036056.mlw
path: /opt/CAPEv2/storage/binaries/f73142dcb13267a5d61eabbbf86e077533f68a10119e3387a893262a98d21d90
crc32: 42D69CD3
md5: 10090fe8df4d35036056064725511aff
sha1: 611c972fc090ae31ee73c64d30804077a197c255
sha256: f73142dcb13267a5d61eabbbf86e077533f68a10119e3387a893262a98d21d90
sha512: d0bad05966edaf7b9b8c2462b50443679432177ce6b6d68343fb441404339c82f27665b414f868220f4484322487c1afd35dc3addead129e531fd2bcfa244359
ssdeep: 49152:P45lFT1XjvjbTFYTFXsT1XjvjbTFTTTFE45lFT1XjvjbTFYTFXsT17jvjbTFTTTG:P23z792az7XE23z792av7XE23m
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18E36C022E2908433D1F33A3DDE5BD3A55A297E502924554B26E83C8F7F367833926397
sha3_384: 4db45f16575c2f14681d1a5674e71f86675c3416469fa4cda80f404719eff3fb2aa0d3a9d5f0ff8b0880a2dce6244228
ep_bytes: 558bec83c4f0b8e42c4500e84034fbff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan.Win32.Buzus.mwwv also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ProcessHijack.@NZ@amu6iAmb
FireEyeGeneric.mg.10090fe8df4d3503
CAT-QuickHealTrojan.Buzus.16579
McAfeeGeneric.bov
MalwarebytesGeneric.Trojan.Delf.DDS
ZillyaTrojan.Buzus.Win32.132543
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0059e23b1 )
K7GWTrojan ( 0059e23b1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZelphiF.36132.@NZ@amu6iAmb
CyrenW32/Injector.BKV.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Injector.BKB
APEXMalicious
ClamAVWin.Ransomware.Buzus-9980395-0
KasperskyTrojan.Win32.Buzus.mwwv
BitDefenderGen:Trojan.ProcessHijack.@NZ@amu6iAmb
NANO-AntivirusTrojan.Win32.Buzus.drxdi
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10b2ab3d
EmsisoftGen:Trojan.ProcessHijack.@NZ@amu6iAmb (B)
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.Inject1.3478
VIPREGen:Trojan.ProcessHijack.@NZ@amu6iAmb
TrendMicroTROJ_BUZUS.BIR
McAfee-GW-EditionBehavesLike.Win32.CoinMiner.tc
Trapminesuspicious.low.ml.score
SophosTroj/Remhead-A
SentinelOneStatic AI – Suspicious PE
GDataWin32.Trojan.PSE.14U1KJJ
JiangminTrojan/Buzus.aaag
GoogleDetected
AviraTR/ATRAPS.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Win32.Buzus
XcitiumTrojWare.Win32.Buzus.AKA@1qoqb7
ArcabitTrojan.ProcessHijack.ED14522
ZoneAlarmTrojan.Win32.Buzus.mwwv
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Buzus.R7579
Acronissuspicious
VBA32BScope.Trojan.MulDrop
ALYacGen:Trojan.ProcessHijack.@NZ@amu6iAmb
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_BUZUS.BIR
RisingTrojan.Injector!1.E2A0 (CLASSIC)
YandexTrojan.GenAsa!E7B6B0Ct0SE
IkarusTrojan.Win32.Buzus
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Injector.BKB!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Trojan.Win32.Buzus.mwwv?

Trojan.Win32.Buzus.mwwv removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment