Trojan

What is “Trojan:Win32/Bunitu.PVK!MTB”?

Malware Removal

The Trojan:Win32/Bunitu.PVK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Bunitu.PVK!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the embedded pe malware family
  • Attempts to identify installed AV products by registry key
  • Operates on local firewall’s policies and settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Bunitu.PVK!MTB?


File Info:

name: CDE340D1EF540F9538C9.mlw
path: /opt/CAPEv2/storage/binaries/12dc4c44b0bdbe2efb8d10de14b09682589069e3f2ea0c82b21c4270455d199d
crc32: CCBF9FD0
md5: cde340d1ef540f9538c99ed22b315b71
sha1: 0fab149174750bb23f354646af1fdef7345fcc7a
sha256: 12dc4c44b0bdbe2efb8d10de14b09682589069e3f2ea0c82b21c4270455d199d
sha512: 1d4f0e1c9d08ec11c57ae9f553d965dc4834268c447dd52ed697c55cb525ddb821bcf9ffc48ed30506fabec92d9de7601edacb33b0cf224b87d28c119b843912
ssdeep: 3072:D3iwQXU2W2GZiawgphLLJOvnEAKVlG+FSczlcSJMBfsTIxsgL+2Jp6XT6rUdm4+B:D3idU20ZiawgphLLJrtVptJuVb9lC+B
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T163549D11B8808436D673293A0538E6B249BEB8310D759ACF67E80D799FB44D1B725F3B
sha3_384: 0a7bce8d75eeb98b72b4768b24055f890f56b4c54b6e8350432a5e0e138938cacd69f2c18bb371a060b23ccb8cbff441
ep_bytes: e8ad030000e960feffff558bec8b4508
timestamp: 2018-04-06 02:17:26

Version Info:

0: [No Data]

Trojan:Win32/Bunitu.PVK!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.GandCrab.557
FireEyeGeneric.mg.cde340d1ef540f95
CAT-QuickHealTrojan.Chapak.ZZ6
SkyhighBehavesLike.Win32.Generic.dh
McAfeeGenericRXEP-RX!CDE340D1EF54
MalwarebytesMachineLearning/Anomalous.95%
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052d2161 )
AlibabaTrojan:Win32/Bunitu.ali1000105
K7GWTrojan ( 0052d2161 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Banker1.BOMK
SymantecPacked.Generic.525
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.GFHF
CynetMalicious (score: 100)
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.GandCrab.557
NANO-AntivirusTrojan.Win32.Banker1.ezpbaq
AvastWin32:Evo-gen [Trj]
SophosMal/GandCrab-D
F-SecurePotentialRisk.PUA/IStartSurf.M
DrWebTrojan.PWS.Banker1.27362
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Ransom.GandCrab.557 (B)
IkarusTrojan.Win32.Crypt
JiangminTrojanDownloader.Upatre.aiyb
AviraPUA/IStartSurf.M
Antiy-AVLTrojan/Win32.Kryptik
Kingsoftmalware.kb.a.1000
MicrosoftTrojan:Win32/Bunitu.PVK!MTB
XcitiumMalware@#cceab4bd222z
ArcabitTrojan.Ransom.GandCrab.557
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.GandCrab.557
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C2456398
BitDefenderThetaGen:NN.ZexaF.36802.ryW@ae7@LFe
ALYacTrojan.Bunitu
MAXmalware (ai score=94)
VBA32BScope.Trojan.Chapak
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_MALREP.THDAOAH
RisingTrojan.Kryptik!1.C2B4 (CLASSIC)
YandexTrojan.GenAsa!8Al7t0IL6CA
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.GFHF!tr
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.1ef540
DeepInstinctMALICIOUS
alibabacloudTrojan.Win.UnkAgent

How to remove Trojan:Win32/Bunitu.PVK!MTB?

Trojan:Win32/Bunitu.PVK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment