Spy Trojan

TrojanSpy:Win32/Buhtrap (file analysis)

Malware Removal

The TrojanSpy:Win32/Buhtrap is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Buhtrap virus can do?

  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid

How to determine TrojanSpy:Win32/Buhtrap?


File Info:

name: C6E9D7280F77977A6968.mlw
path: /opt/CAPEv2/storage/binaries/1ce29e2c781dffce2c135856caef153dff20a654e3b2bec326d1a6f7e8c1a8f6
crc32: 4C489244
md5: c6e9d7280f77977a6968722e8124f51c
sha1: c0f380d82b637303c274ca895a9f650e5a90a4f6
sha256: 1ce29e2c781dffce2c135856caef153dff20a654e3b2bec326d1a6f7e8c1a8f6
sha512: df7f236bae8b007b578db56fce270ba840842e8ee7688a8dab4e64958d133a577addf2cfd6301c28942142dfcdfe23f75c2679a28476ea464801d9bad17ea8b5
ssdeep: 768:mzJxZvlYnscv28D+bh/8mfwGGI0XPU+0CORBAlpwKDjeuEe6W11nLRjY:mzJ/lGscv2HbhhAU/1ROWS681ndjY
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T14A432902F59880B5F2F15678B6F46726147AAF727776B5CB91A3209C19A04F3FA39303
sha3_384: 1565ccbc99520dc2be4300e07eae2d6579869d95b94721af9b34e4fefe9bc9235430fc42f943eaa2d5e3cb577989cc30
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2019-06-02 12:03:54

Version Info:

CompanyName: TODO:
FileDescription: TODO:
FileVersion: 1.0.0.1
InternalName: grabber.exe
LegalCopyright: Copyright (C) 2018
OriginalFilename: grabber.exe
ProductName: TODO:
ProductVersion: 1.0.0.1
Translation: 0x0419 0x04b0

TrojanSpy:Win32/Buhtrap also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Buhtrap.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Barys.326790
FireEyeGeneric.mg.c6e9d7280f77977a
SkyhighRDN/Generic PWS.y
ALYacGen:Variant.Barys.326790
Cylanceunsafe
SangforSpyware.Win32.Buhtrap.Vvio
K7AntiVirusSpyware ( 0054f6761 )
AlibabaTrojanSpy:Win32/APosT.1853f34e
K7GWSpyware ( 0054f6761 )
BitDefenderThetaGen:NN.ZedlaF.36804.du8@aqTmu1pk
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Buhtrap.AK
TrendMicro-HouseCallTROJ_GEN.R002C0DC924
Paloaltogeneric.ml
KasperskyTrojan.Win32.APosT.iwr
BitDefenderGen:Variant.Barys.326790
NANO-AntivirusTrojan.Win32.Stealer.frxpsq
AvastWin32:Trojan-gen
TencentWin32.Trojan.Apost.Xmhl
EmsisoftGen:Variant.Barys.326790 (B)
F-SecureTrojan.TR/AD.Fareit.ckfgt
DrWebTrojan.PWS.Stealer.26394
ZillyaTrojan.Buhtrap.Win32.45
TrendMicroTROJ_GEN.R002C0DC924
SophosMal/Generic-S
JiangminTrojan.APosT.bhv
VaristW32/Fareit.IV.gen!Eldorado
AviraTR/AD.Fareit.ckfgt
Antiy-AVLTrojan/Win32.Ta505
KingsoftWin32.Trojan.Agent.gen
MicrosoftTrojanSpy:Win32/Buhtrap
XcitiumMalware@#231gu5zluty3
ArcabitTrojan.Barys.D4FC86
ViRobotTrojan.Win32.Z.Agent.58880.JUU
ZoneAlarmTrojan.Win32.APosT.iwr
GDataGen:Variant.Barys.326790
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Buhtrap.C3283701
McAfeeRDN/Generic PWS.y
GoogleDetected
VBA32BScope.TrojanPSW.Stealer
PandaTrj/GdSda.A
RisingSpyware.Buhtrap!1.F80A (CLASSIC)
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Malware.74363707.susgen
FortinetW32/Buhtrap.AK!tr.spy
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
alibabacloudTrojan[spy]:Win/Buhtrap.AK

How to remove TrojanSpy:Win32/Buhtrap?

TrojanSpy:Win32/Buhtrap removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment