Trojan

Trojan:Win32/Busky.D removal instruction

Malware Removal

The Trojan:Win32/Busky.D is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Busky.D virus can do?

  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Performs HTTP requests potentially not found in PCAP.
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Deletes executed files from disk
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Busky.D?


File Info:

name: 0B5D4F1BF424908E4B6D.mlw
path: /opt/CAPEv2/storage/binaries/1c4dde9a6fa5ad6b718881e636bdf71f410f6f975f583dedd5572ed77af5645d
crc32: 17A68C5D
md5: 0b5d4f1bf424908e4b6d976e0dce5595
sha1: 59c2aaf60505f8d5eaecb2ccbff768984309712c
sha256: 1c4dde9a6fa5ad6b718881e636bdf71f410f6f975f583dedd5572ed77af5645d
sha512: f474512649f888a8eea428ad7f68106407aa52796e09b297cf8aa26b8e6f2f3f42464692e97f6c6074eb63eec5e8a64d83cb9ee48e6e40d1ad42cbc015f0f29b
ssdeep: 768:Ex0d3nQuZOnxd6dg2+c52E0ystHyM0JJifxoJ0V5b2gNjyjKHe4jNZCVaNF:ExO3nQuexdAj1oE0yssLyKcb2Qjikpnl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T101230266E5549E63D3A6F3750B3ECE2B320D383477E9918D89E24DE2D807487B09DCA4
sha3_384: 7ace65148b0aad8a3d3ef3e4bfe5a6165f7cf66937fe91a0ce3235bf4f2214dcc03d1125e9e50b3b50c828e1a34625d2
ep_bytes: 60be00a040008dbe0070ffff5783cdff
timestamp: 2007-09-24 18:43:00

Version Info:

0: [No Data]

Trojan:Win32/Busky.D also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Zlob.a!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanDropped:Trojan.Otuboh.Gen
FireEyeGeneric.mg.0b5d4f1bf424908e
SkyhighBehavesLike.Win32.Generic.pc
ALYacDropped:Trojan.Otuboh.Gen
Cylanceunsafe
VIPREDropped:Trojan.Otuboh.Gen
SangforTrojan.Win32.Busky.D
K7AntiVirusTrojan ( 004a745d1 )
BitDefenderDropped:Trojan.Otuboh.Gen
K7GWTrojan ( 004a745d1 )
Cybereasonmalicious.60505f
BitDefenderThetaAI:Packer.7237FB2F1B
VirITTrojan.Win32.Zlob.NP
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32Win32/Adware.UltimateDefender
APEXMalicious
ClamAVWin.Trojan.Zlob-2938
KasperskyTrojan-Downloader.Win32.Zlob.diq
AlibabaTrojanDownloader:Win32/Obfuscated.7edea1bf
NANO-AntivirusTrojan.Win32.Zlob.wxys
ViRobotTrojan.Win32.Downloader.46088
RisingTrojan.DL.Win32.Agent.zmh (CLASSIC)
SophosMal/EncPk-DG
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Obfuscated.based.1
ZillyaDownloader.Zlob.Win32.12345
TrendMicroTROJ_ZLOB.DGX
EmsisoftDropped:Trojan.Otuboh.Gen (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=100)
JiangminTrojanDownloader.Zlob.cgj
GoogleDetected
AviraTR/Crypt.XPACK.Gen
VaristW32/Backdoor.ZQSY-1716
Antiy-AVLTrojan[Downloader]/Win32.Zlob
KingsoftWin32.Troj.Undef.a
MicrosoftTrojan:Win32/Busky.D
XcitiumTrojWare.Win32.Magania.~AI@f80t8
ArcabitTrojan.Otuboh.Gen
ZoneAlarmTrojan-Downloader.Win32.Zlob.diq
GDataDropped:Trojan.Otuboh.Gen
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Obfuscated.R28735
McAfeeGenericRXAA-FA!0B5D4F1BF424
DeepInstinctMALICIOUS
VBA32BScope.Trojan-Downloader.Googlya.B.Obfs
MalwarebytesMalware.Heuristic.2047
PandaMalicious Packer
TrendMicro-HouseCallTROJ_ZLOB.DGX
TencentWin32.Trojan-Downloader.Zlob.Xmhl
YandexTrojan.DR.Zlob!etel4ScADMg
IkarusTrojan.Win32.Obfuscated
MaxSecureTrojan.Malware.696436.susgen
FortinetW32/Obfuscated.GX!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan:Win32/Busky.D?

Trojan:Win32/Busky.D removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment