Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | October 2008 (4.34) |
| Protection available since | 20 August 2008 08:43:07 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Buzus-M is a Trojan for the Windows platform
When first run, the Trojan creates the following files:
<Temp>\TEMP01.RAR (detected as Troj/Buzus-M)
<System>\chkdsks.exe (detected as Mal/Generic-A)
<System>\ciadvs.exe (detected as Troj/Buzus-M)
<System>\rar.exe (File not malicious)
and may attempt to download the following:
<System>\Monitored.dat (data file that may be safely deleted)
The following registry entries are set:
HKCU\Software\Microsoft\CurrentVersion\Policies\Explorer\Run
NT Printing Services
chkdsks.exe
HKCU\Software\Microsoft\CurrentVersion\Policies\Explorer\Run
Windows Printing Driver
ciadvs.exe
HKLM\SOFTWARE\Licenses\
HKCR\CLSID\{29A5EA88-29A5-EA88-29A5-EA8829A5EA88}
