Trojan

Trojan.Win32.Buzus.ydmw removal tips

Malware Removal

The Trojan.Win32.Buzus.ydmw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Buzus.ydmw virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid

How to determine Trojan.Win32.Buzus.ydmw?


File Info:

name: 4CA50C17EAB114F0472B.mlw
path: /opt/CAPEv2/storage/binaries/79df5549fa105942231ad755be4210a06fb86468c83c959c62b8559975c9aacc
crc32: 3CA21574
md5: 4ca50c17eab114f0472ba0026c7d4a17
sha1: 018d55f48dc3c4eb2f2a2a7d3624be2d69f4c8f6
sha256: 79df5549fa105942231ad755be4210a06fb86468c83c959c62b8559975c9aacc
sha512: c7177f904db663bd3faa82163e37477a9f9937600cf32f6156523649cb8fe85dc340a4cbeec2acf9a3b697f4758dd6b18c1712ecd0a31add7314bd606be209d3
ssdeep: 3072:1ByK8qEDZ+XFAqi9DHCxPm7nlSZ3X3b2ox3z/2Zo1I:XMDWFm4x+7QiODe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D684AC1ADD702063DB6032F358A272A6516BEE77D1007E27B9D0E9390BFC7C697C2925
sha3_384: 8be3c3246082be4dad73e35b55490d242a332e3ed743340d63344ef56ebc88f25aeeb6e9e80fc8017e466abfd531f811
ep_bytes: 6820154000e8eeffffff000000000000
timestamp: 2017-01-03 22:00:50

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Sharp
FileDescription: Sidolla Parda Liccanti
ProductName: Grosserere
FileVersion: 1.00
ProductVersion: 1.00
InternalName: Rdfrt
OriginalFilename: Rdfrt.exe

Trojan.Win32.Buzus.ydmw also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Buzus.4!c
CynetMalicious (score: 100)
FireEyeGeneric.mg.4ca50c17eab114f0
CAT-QuickHealTrojan.Buzus.S802574
McAfeeGeneric.abb
CylanceUnsafe
VIPRETrojan.GenericKD.4161043
Sangfor[MICROSOFT VISUAL BASIC 5.0]
K7AntiVirusSpyware ( 004b90fc1 )
AlibabaTrojanPSW:Win32/Buzus.1435b01b
K7GWSpyware ( 004b90fc1 )
Cybereasonmalicious.7eab11
VirITTrojan.Win32.ZBot.FSO
CyrenW32/Zbot.FEOZ-4330
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Zbot.ABV
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packer.VbPack-0-6334882-0
KasperskyTrojan.Win32.Buzus.ydmw
BitDefenderTrojan.GenericKD.4161043
NANO-AntivirusTrojan.Win32.Buzus.eopeme
ViRobotTrojan.Win32.Z.Zbot.385024.CG
MicroWorld-eScanTrojan.GenericKD.4161043
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.114b1bb2
Ad-AwareTrojan.GenericKD.4161043
SophosML/PE-A + Mal/Generic-L
ComodoMalware@#3jqw5dyb16s9s
DrWebTrojan.Siggen7.2536
ZillyaTrojan.Buzus.Win32.126879
TrendMicroTrojanSpy.Win32.LOKI.SM.hp
McAfee-GW-EditionGeneric.abb
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.4161043 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Agent.J62GO1
JiangminTrojan.Buzus.buv
AviraTR/Spy.Zbot.mhlvs
Antiy-AVLTrojan/Generic.ASMalwS.AA
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ArcabitTrojan.Generic.D3F7E13
MicrosoftPWS:Win32/Zbot!VM
AhnLab-V3Win-Trojan/VBKrypt.RP.X1764
VBA32BScope.Trojan.Buzus
ALYacTrojan.GenericKD.4161043
MAXmalware (ai score=100)
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SM.hp
RisingTrojan.Spy.Win32.Zbot.hxe (CLASSIC)
YandexTrojan.Buzus!7bTnx/aHC9Y
IkarusTrojan-Spy.Agent
FortinetW32/Injector.DKEA!tr
BitDefenderThetaGen:NN.ZevbaF.34786.xm0@aWbyzLci
AVGWin32:Malware-gen
PandaTrj/WLT.C
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Win32.Buzus.ydmw?

Trojan.Win32.Buzus.ydmw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment