Trojan

About “Trojan:Win32/BuerLoader!MSR” infection

Malware Removal

The Trojan:Win32/BuerLoader!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/BuerLoader!MSR virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Anomalous binary characteristics

Related domains:

documentssign-api.com

How to determine Trojan:Win32/BuerLoader!MSR?


File Info:

crc32: 0694B458
md5: 65d160b89f6f563bca60461adc71f979
name: 65D160B89F6F563BCA60461ADC71F979.mlw
sha1: a61e74e58d3c5eee4a127dd108cff9dbbcfc8ef1
sha256: 3abed86f46c8be754239f8c878f035efaae91c33b8eb8818c5bbed98c4d9a3ac
sha512: d7dc4a53fda4880ee689e1e39129af4100f9a877a4ebb8f9915554c7739a956011338bcd7a43726261f0041f1a5976ffc044475e7ceb9b08073cd037bc59a88d
ssdeep: 24576:cRGTl08SERfOVXuwPjCO47i4QhPMMBxzLic2VKJz16To2Dv4et08wRYB7PAe:cMFls6Omi4QTHLic0kOowd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 My Company. All rights reserved.
InternalName: myfile.exe
FileVersion: 1.0.0.0
CompanyName: My Company
ProductName: My App
ProductVersion: 1.0.0.0
FileDescription: Description of my application
OriginalFilename: myfile.exe
Translation: 0x0409 0x04b0

Trojan:Win32/BuerLoader!MSR also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0057b2e21 )
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
CAT-QuickHealTrojan.FlyStudio
ALYacTrojan.BuerLoader
CylanceUnsafe
ZillyaDropper.Agent.Win32.452858
SangforTrojan.Win32.Wacatac.B
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/BuerLoader.214aa67a
K7GWTrojan ( 0057b2e21 )
Cybereasonmalicious.58d3c5
CyrenW32/Trojan.QFWC-8684
SymantecTrojan.Gen.MBT
ESET-NOD32NSIS/Injector.AKI
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Dropper.Win32.Agent.gen
BitDefenderTrojan.GenericKD.46133711
ViRobotDropper.S.Agent.1549932
MicroWorld-eScanTrojan.GenericKD.46133711
Ad-AwareTrojan.GenericKD.46133711
SophosMal/Generic-S + Troj/Inject-GWA
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.BUERLOADER.B
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.65d160b89f6f563b
EmsisoftTrojan.GenericKD.46133711 (B)
JiangminTrojan.Injects.tn
AviraHEUR/AGEN.1142075
MicrosoftTrojan:Win32/BuerLoader!MSR
ArcabitTrojan.Generic.D2BFF1CF
GDataTrojan.GenericKD.46133711
AhnLab-V3Trojan/Win.Generic.C4449684
McAfeeArtemis!65D160B89F6F
MAXmalware (ai score=89)
VBA32TrojanDropper.Agent
MalwarebytesRiskWare.FlyStudio
PandaTrj/CI.A
TrendMicro-HouseCallTrojan.Win32.BUERLOADER.B
RisingTrojan.Injector/NSIS!1.BFBB (CLASSIC)
FortinetNSIS/Injector.AKF!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan:Win32/BuerLoader!MSR?

Trojan:Win32/BuerLoader!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment