Published Jun 21, 2012|Updated Mar 08, 2018


Severe |Detected with Windows Defender Antivirus

Aliases: Trojan.Win32.Buzus.ltcn (Kaspersky) Troj/Agent-WSW (Sophos)


Windows Defender Antivirus  detects and removes this threat.

This trojan can download and install other programs without your consent, including other malware.

See the Dofoil family description for more information.

On March 6, 2018, behavior monitoring and machine learning technologies in Windows Defender Antivirus stopped a Dofoil variant (also known as Smoke Loader) that tried to infect more than 400,000 computers. The massive campaign aimed to install a cryptocurrency miner that uses victim computers' resources for coin mining purposes. Learn how artificial intelligence stopped the attack within minutes:

Behavior monitoring combined with machine learning spoils a massive Dofoil coin mining campaign


Latest news