Trojan

TrojanProxy:Win32/Bunitu.Q!bit removal guide

Malware Removal

The TrojanProxy:Win32/Bunitu.Q!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanProxy:Win32/Bunitu.Q!bit virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by registry key
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanProxy:Win32/Bunitu.Q!bit?


File Info:

crc32: C4557835
md5: f3262cf1fc20d46582975e19731fffb6
name: F3262CF1FC20D46582975E19731FFFB6.mlw
sha1: d23541428590e2857083b99f0295b6a98c6c64df
sha256: fd581460de1fc1a912cba1648656cc057f90cb46f160bf93cb5154d6303de7a3
sha512: 404f28fde2429c6190add7b2d9f9eaf9f5b3926ae58c493345c6a4cbd7a476d0819530e717b7e188c4bf551d71dfad3b024cdd919c30316e4117ddb16f2e7904
ssdeep: 3072:/Y0cpwE5T1mi3bQEtAscyIdytBrMOvwJVg7vMY3nTc6gYQEFkkgEPpTth4Q5dT+:fB63bQ1sRQyDpvE8VLg6hL9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileDescription: DAP Error Report
CompanyName: Speedbit Ltd.
Translation: 0x0409 0x04b0

TrojanProxy:Win32/Bunitu.Q!bit also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Injector.CKN
FireEyeGeneric.mg.f3262cf1fc20d465
CAT-QuickHealRansom.Cerber.A4
Qihoo-360Generic/Trojan.e72
McAfeePacked-MU!F3262CF1FC20
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Malicious.4!c
SangforMalware
K7AntiVirusTrojan ( 0050c0801 )
BitDefenderTrojan.Injector.CKN
K7GWTrojan ( 0050c0801 )
Cybereasonmalicious.1fc20d
BitDefenderThetaGen:NN.ZexaF.34804.Kq0@aGzxPkai
CyrenW32/S-43e50be1!Eldorado
SymantecTrojan Horse
BaiduWin32.Trojan.Kryptik.bix
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Ceao-6982077-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Bunitu.ali1000105
NANO-AntivirusTrojan.Win32.Yakes.elxlir
RisingTrojan.Kryptik!1.A877 (CLOUD)
Ad-AwareTrojan.Injector.CKN
SophosMal/Generic-S + Mal/CerberN-A
ComodoTrojWare.Win32.Ransom.Cerber.BF@6tebck
F-SecureHeuristic.HEUR/AGEN.1106825
DrWebTrojan.Siggen7.9985
ZillyaTrojan.Yakes.Win32.63281
TrendMicroRansom_HPCERBER.SMALY5A
McAfee-GW-EditionBehavesLike.Win32.Dropper.ht
EmsisoftTrojan.Injector.CKN (B)
IkarusTrojan-Proxy.Agent
JiangminTrojan.Yakes.ugu
AviraHEUR/AGEN.1106825
MAXmalware (ai score=81)
Antiy-AVLTrojan/Win32.Yakes
MicrosoftTrojanProxy:Win32/Bunitu.Q!bit
ArcabitTrojan.Injector.CKN
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Injector.CKN
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/RansomCrypt.Gen
Acronissuspicious
VBA32BScope.Trojan.Menti
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.FONP
TrendMicro-HouseCallRansom_HPCERBER.SMALY5A
TencentMalware.Win32.Gencirc.10b57814
YandexTrojan.GenAsa!48GFITBYl2M
SentinelOneStatic AI – Malicious PE – Ransomware
eGambitUnsafe.AI_Score_100%
FortinetW32/Kryptik.HGZD!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove TrojanProxy:Win32/Bunitu.Q!bit?

TrojanProxy:Win32/Bunitu.Q!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment