Trojan

TrojanProxy:Win32/Bunitu.HA!MTB removal guide

Malware Removal

The TrojanProxy:Win32/Bunitu.HA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanProxy:Win32/Bunitu.HA!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanProxy:Win32/Bunitu.HA!MTB?


File Info:

crc32: 9A289F15
md5: 17b2ea7efe980d80b8db25aa919cc5ed
name: 3ec33f3ad59cd84c5c66f925d7c278835631b8d9f9616730371c3ee034153e73
sha1: 117575f82aae9df166325856b54bf26997794c03
sha256: 3ec33f3ad59cd84c5c66f925d7c278835631b8d9f9616730371c3ee034153e73
sha512: c9a0506abdd8992c64dd16fb0dc71ab6a23e484f9a4dea51d7385f459599a792949dc84ebc2bae3abfd8c601693388d849d93b7b53986d50f7147e55edb16610
ssdeep: 1536:KCpip1tUyBsjbKmc3jIg7HSamn/Mj4W6j3S/Zw+MscsgS1i3BRuyvZ9sTgXPS1I:Kb5g2mc06HSamn/2AWbwvpS1IVB5N
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: All rights reserved. Portrait Displays, Inc.
InternalName: pdisrvc
FileVersion: 2,2,22,002
CompanyName: Portrait Displays, Inc.
Comments: Service to facilitate ddc/ci communication with monitors.
ProductName: pdisrvc
ProductVersion: 2,2,22,002
FileDescription: pdisrvc
OriginalFilename: pdisrvc
Translation: 0x0409 0x04b0

TrojanProxy:Win32/Bunitu.HA!MTB also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanGen:Variant.Razy.596767
FireEyeGeneric.mg.17b2ea7efe980d80
McAfeeGenericRXJK-DN!17B2EA7EFE98
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0055e42d1 )
BitDefenderGen:Variant.Razy.596767
K7GWTrojan ( 0055e42d1 )
Cybereasonmalicious.82aae9
ArcabitTrojan.Razy.D91B1F
Invinceaheuristic
F-ProtW32/Cridex.CW
SymantecPacked.Generic.459
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyHEUR:Trojan-Downloader.Win32.Cridex.vho
AlibabaTrojanDownloader:Win32/Kryptik.fbbb97d1
NANO-AntivirusTrojan.Win32.Dridex.gsvwbg
AegisLabHacktool.Win32.Krap.lKMc
RisingTrojan.Kryptik!1.C177 (CLASSIC)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Razy.596767 (B)
F-SecureTrojan.TR/Crypt.Agent.wwfzr
DrWebTrojan.Dridex.611
MaxSecureTrojan.Malware.74663047.susgen
ZillyaTrojan.Kryptik.Win32.1899198
TrendMicroTROJ_GEN.R02FC0DA620
McAfee-GW-EditionBehavesLike.Win32.Generic.dm
FortinetW32/GenKryptik.EBMP!tr
Trapminesuspicious.low.ml.score
SophosMal/Cerber-AL
IkarusTrojan.Win32.Dridex
CyrenW32/Cridex.OKOT-3804
JiangminTrojanDownloader.Cridex.js
AviraTR/Crypt.Agent.wwfzr
MAXmalware (ai score=86)
Antiy-AVLTrojan[Downloader]/Win32.Cridex
MicrosoftTrojanProxy:Win32/Bunitu.HA!MTB
ZoneAlarmHEUR:Trojan-Downloader.Win32.Cridex.vho
AhnLab-V3Trojan/Win32.Cridex.R307641
Acronissuspicious
VBA32BScope.TrojanDownloader.Cridex
ALYacGen:Variant.Razy.596767
TACHYONTrojan-Downloader/W32.Cridex.270848
Ad-AwareGen:Variant.Razy.596767
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.GZYL
TrendMicro-HouseCallTrojanSpy.Win32.DRIDEX.SMBB.hp
TencentMalware.Win32.Gencirc.10b8aa71
YandexTrojan.DL.Cridex!+tdiWexynAs
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_93%
GDataGen:Variant.Razy.596767
BitDefenderThetaGen:NN.ZexaF.34100.qq0@aOrZYlli
AVGWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/HEUR/QVM20.1.685D.Malware.Gen

How to remove TrojanProxy:Win32/Bunitu.HA!MTB?

TrojanProxy:Win32/Bunitu.HA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment