Sophos

Troj/Buzus-M

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Drops more malware
  • Installs itself in the registry
Included in our products from October 2008 (4.34)
Protection available since 20 August 2008 08:43:07 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Buzus-M is a Trojan for the Windows platform

When first run, the Trojan creates the following files:

<Temp>\TEMP01.RAR (detected as Troj/Buzus-M)
<System>\chkdsks.exe (detected as Mal/Generic-A)
<System>\ciadvs.exe (detected as Troj/Buzus-M)
<System>\rar.exe (File not malicious)

and may attempt to download the following:

<System>\Monitored.dat (data file that may be safely deleted)

The following registry entries are set:

HKCU\Software\Microsoft\CurrentVersion\Policies\Explorer\Run
NT Printing Services
chkdsks.exe

HKCU\Software\Microsoft\CurrentVersion\Policies\Explorer\Run
Windows Printing Driver
ciadvs.exe

HKLM\SOFTWARE\Licenses\
HKCR\CLSID\{29A5EA88-29A5-EA88-29A5-EA8829A5EA88}

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer