Malware

How to remove “Win32:Buzus-QM [Trj]”?

Malware Removal

The Win32:Buzus-QM [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Buzus-QM [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Creates Zeus (Banking Trojan) mutexes
  • Anomalous binary characteristics

How to determine Win32:Buzus-QM [Trj]?


File Info:

name: 96D56F552B3DBF4CE9D0.mlw
path: /opt/CAPEv2/storage/binaries/15e1b14a8745d3d366e8424705b618b3bd07ae43e4674eb65308ee1c8f57c2d7
crc32: C4CE22FF
md5: 96d56f552b3dbf4ce9d08bb4306ea441
sha1: 22fa1e0acf99b6f3577de3dfba825004f7b3471e
sha256: 15e1b14a8745d3d366e8424705b618b3bd07ae43e4674eb65308ee1c8f57c2d7
sha512: 3d32dddfe3220e0c98a309387d8663357d4822411c98ee1adb756e5443af431c9e11401844d724b54d2c746376abd7554b14200202dfa1435d1e7233b19ee06f
ssdeep: 12288:31kV+DfbnrkOZ9NzD6A8TyNp7giIASUf/uZifDp8zIY/0Q5YOVuiNoxeWQsR:Fk8TAOZ9N3v8a6iJ+YSzIoYEhohQsR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1310523DB9D460B27E3326EBBCC77FC4C4C984D63991289ABF765806997C98D6100E24F
sha3_384: 6231b6f7859746c44e8708e8175ad430f3a87523ef51861ca55f55a75c1749438953ba2955378e54f840d3b0ed220b0f
ep_bytes: 558bec83ec48565764a1300000008b70
timestamp: 1970-08-24 04:05:18

Version Info:

0: [No Data]

Win32:Buzus-QM [Trj] also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Patched.CM
FireEyeGeneric.mg.96d56f552b3dbf4c
McAfeePohern
CylanceUnsafe
VIPRETrojan.Patched.CM
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
K7GWTrojan ( 7000000f1 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Patched.CM
VirITTrojan.Win32.Packed.TA
CyrenW32/SuspPack.BD.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.K
ZonerProbably Heur.ExeHeaderL
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Zbot.adec
BitDefenderTrojan.Patched.CM
NANO-AntivirusTrojan.Win32.Buzus.sckb
AvastWin32:Buzus-QM [Trj]
Ad-AwareTrojan.Patched.CM
SophosML/PE-A
ComodoTrojWare.Win32.TrojanSpy.Zbot.AAB@39gfyr
DrWebTrojan.Packed.494
ZillyaTrojan.Zbot.Win32.62971
McAfee-GW-EditionBehavesLike.Win32.Autorun.bc
Trapminemalicious.high.ml.score
EmsisoftTrojan.Patched.CM (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Buzus.cwz
AviraBDS/Hupigon.Gen
Antiy-AVLTrojan/Generic.ASMalwS.31
MicrosoftVirTool:Win32/DelfInject.gen!L
ViRobotTrojan.Win32.Buzus.65902
ZoneAlarmPacked.Multi.SuspiciousPacker.gen
GDataTrojan.Patched.CM
GoogleDetected
Acronissuspicious
BitDefenderThetaAI:Packer.B2E7A7E11D
ALYacTrojan.Patched.CM
MAXmalware (ai score=85)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesMachineLearning/Anomalous.100%
RisingTrojan.Bulta!8.35D (TFE:4:pYiAXQ36kKK)
IkarusVirus.Win32.Virut.q
FortinetW32/LdPinch.NCT!tr
AVGWin32:Buzus-QM [Trj]
Cybereasonmalicious.52b3db

How to remove Win32:Buzus-QM [Trj]?

Win32:Buzus-QM [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment