Adware Reports malware removal guides and threat research Updated security instructions for Windows users
Threat report

TrojanSpy:Win32/Buhtrap (file analysis)

Published May 3, 2024 Spy category 3 min read
Report context

What to verify before removal

TrojanSpy:Win32/Buhtrap (file analysis) deserves a credential-safety review because this spy label can overlap with remote access, browser data theft, or persistence after reboot. Cleanup should include scanning the file, removing the persistence point, and rotating exposed passwords from a clean device.

Start by comparing the local file name with C6E9D7280F77977A6968.mlw, then review the behavior notes for credential theft, browser data access, remote-control activity, and persistence after reboot. This helps separate a matching detection from a different file that only shares a similar alert name.

Observed file
C6E9D7280F77977A6968.mlw
  • Compare the suspicious file name with C6E9D7280F77977A6968.mlw.
  • Confirm the detection name matches TrojanSpy:Win32/Buhtrap (file analysis) before removing related files.
  • Review the report for credential theft, browser data access, remote-control activity, and persistence after reboot so the cleanup is based on observed behavior, not only the label.
  • After cleanup, rotate passwords from a clean device and review browser sessions or saved credentials.

The TrojanSpy:Win32/Buhtrap is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What TrojanSpy:Win32/Buhtrap virus can do?

  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid

How to determine TrojanSpy:Win32/Buhtrap?


File Info:

name: C6E9D7280F77977A6968.mlw
path: /opt/CAPEv2/storage/binaries/1ce29e2c781dffce2c135856caef153dff20a654e3b2bec326d1a6f7e8c1a8f6
crc32: 4C489244
md5: c6e9d7280f77977a6968722e8124f51c
sha1: c0f380d82b637303c274ca895a9f650e5a90a4f6
sha256: 1ce29e2c781dffce2c135856caef153dff20a654e3b2bec326d1a6f7e8c1a8f6
sha512: df7f236bae8b007b578db56fce270ba840842e8ee7688a8dab4e64958d133a577addf2cfd6301c28942142dfcdfe23f75c2679a28476ea464801d9bad17ea8b5
ssdeep: 768:mzJxZvlYnscv28D+bh/8mfwGGI0XPU+0CORBAlpwKDjeuEe6W11nLRjY:mzJ/lGscv2HbhhAU/1ROWS681ndjY
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T14A432902F59880B5F2F15678B6F46726147AAF727776B5CB91A3209C19A04F3FA39303
sha3_384: 1565ccbc99520dc2be4300e07eae2d6579869d95b94721af9b34e4fefe9bc9235430fc42f943eaa2d5e3cb577989cc30
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2019-06-02 12:03:54

Version Info:

CompanyName: TODO:
FileDescription: TODO:
FileVersion: 1.0.0.1
InternalName: grabber.exe
LegalCopyright: Copyright (C) 2018
OriginalFilename: grabber.exe
ProductName: TODO:
ProductVersion: 1.0.0.1
Translation: 0x0419 0x04b0

TrojanSpy:Win32/Buhtrap also known as:

Bkav W32.AIDetectMalware
Lionic Trojan.Win32.Buhtrap.4!c
Elastic malicious (high confidence)
MicroWorld-eScan Gen:Variant.Barys.326790
FireEye Generic.mg.c6e9d7280f77977a
Skyhigh RDN/Generic PWS.y
ALYac Gen:Variant.Barys.326790
Cylance unsafe
Sangfor Spyware.Win32.Buhtrap.Vvio
K7AntiVirus Spyware ( 0054f6761 )
Alibaba TrojanSpy:Win32/APosT.1853f34e
K7GW Spyware ( 0054f6761 )
BitDefenderTheta Gen:NN.ZedlaF.36804.du8@aqTmu1pk
Symantec ML.Attribute.HighConfidence
ESET-NOD32 Win32/Spy.Buhtrap.AK
TrendMicro-HouseCall TROJ_GEN.R002C0DC924
Paloalto generic.ml
Kaspersky Trojan.Win32.APosT.iwr
BitDefender Gen:Variant.Barys.326790
NANO-Antivirus Trojan.Win32.Stealer.frxpsq
Avast Win32:Trojan-gen
Tencent Win32.Trojan.Apost.Xmhl
Emsisoft Gen:Variant.Barys.326790 (B)
F-Secure Trojan.TR/AD.Fareit.ckfgt
DrWeb Trojan.PWS.Stealer.26394
Zillya Trojan.Buhtrap.Win32.45
TrendMicro TROJ_GEN.R002C0DC924
Sophos Mal/Generic-S
Jiangmin Trojan.APosT.bhv
Varist W32/Fareit.IV.gen!Eldorado
Avira TR/AD.Fareit.ckfgt
Antiy-AVL Trojan/Win32.Ta505
Kingsoft Win32.Trojan.Agent.gen
Microsoft TrojanSpy:Win32/Buhtrap
Xcitium Malware@#231gu5zluty3
Arcabit Trojan.Barys.D4FC86
ViRobot Trojan.Win32.Z.Agent.58880.JUU
ZoneAlarm Trojan.Win32.APosT.iwr
GData Gen:Variant.Barys.326790
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win32.Buhtrap.C3283701
McAfee RDN/Generic PWS.y
Google Detected
VBA32 BScope.TrojanPSW.Stealer
Panda Trj/GdSda.A
Rising Spyware.Buhtrap!1.F80A (CLASSIC)
Ikarus Trojan-Spy.Agent
MaxSecure Trojan.Malware.74363707.susgen
Fortinet W32/Buhtrap.AK!tr.spy
AVG Win32:Trojan-gen
DeepInstinct MALICIOUS
alibabacloud Trojan[spy]:Win/Buhtrap.AK

How to remove TrojanSpy:Win32/Buhtrap?

Recommended second-opinion scan

Verify the infection before changing system settings

Use GridinSoft Anti-Malware to run a full scan, review detected persistence entries, and quarantine confirmed threats before restarting Windows.

Download GridinSoft Anti-Malware
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.