Troj/Buzus-EF exhibits the following characteristics:
Other vendor detection
- Avira
- TR/Dropper.Gen
- Kaspersky
- Trojan.Win32.Buzus.dvzx
Runtime Analysis
Copies Itself To
- F:/svchost.exe
- c:\Documents and Settings\test user\Application Data\Microsoft\svchost.exe
Dropped Files
Registry Keys Created
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run
- Startup
- c:\Documents and Settings\test user\Application Data\Microsoft\svchost.exe
- HKCU\Software\Default
- FileNameActual
- c:\test_item.exe
DNS Requests