Trojan

Trojan:Win32/Bunitucrypt.DE!MTB (file analysis)

Malware Removal

The Trojan:Win32/Bunitucrypt.DE!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Bunitucrypt.DE!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Bunitucrypt.DE!MTB?


File Info:

name: 1677080C5094E36BC78C.mlw
path: /opt/CAPEv2/storage/binaries/af3b67a1b4ced3eb631533b9f46f2b2f9b920f9933ea01d3cd6aeddf1afaa292
crc32: 4347FFAD
md5: 1677080c5094e36bc78c7b1c27c3b6e8
sha1: 949e00d2c94e7d4ebd27d709d761812b7fdf35a3
sha256: af3b67a1b4ced3eb631533b9f46f2b2f9b920f9933ea01d3cd6aeddf1afaa292
sha512: f0a571f9df685cf22c6230e04bd1b67d80030d2ad1e86e721d153283681cc2865e81ce04ec0f89c984c97a0a40ac7ac4e241cb1f47826319b5555d5784486f5a
ssdeep: 24576:YOfNkuu6oLsIWR6ijVDX+QO+AQHnKNbbYrYGC9HK7IP0mo/CnAzG/AD:H60RJXxOJGK1NNAIP0momAzsAD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19F85CF089147E2BBFCFD08A3445090D0C29D7FAA7B128DCDE97AD58A151F482F7B6D86
sha3_384: c076f36746cf97e127a5cd553d010cb9b5383e4c9eeddc0c9768ecaea3f352ebd5bfe476a4f75ff6d5f36bb00932d572
ep_bytes: e808050000e988feffff3b0d58254300
timestamp: 2020-12-01 18:01:01

Version Info:

0: [No Data]

Trojan:Win32/Bunitucrypt.DE!MTB also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
FireEyeGeneric.mg.1677080c5094e36b
CylanceUnsafe
SangforTrojan.Win32.Qshell.kty
K7AntiVirusTrojan ( 0057eb371 )
AlibabaTrojan:Win32/Qshell.264717d3
K7GWTrojan ( 0057eb371 )
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Injector.EPPU
BaiduArchive.Bomb
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan.Win32.Qshell.kty
RisingMalware.AbnormalScript/SFX!1.D9B9 (CLASSIC)
TrendMicroTROJ_GEN.R002C0DLQ21
McAfee-GW-EditionBehavesLike.Win32.Generic.th
SophosMal/Generic-S
GDataWin32.Trojan.BSE.1AX504H
AviraTR/Injector.kckrl
Antiy-AVLGeneric/Generic.APUnArc.1
MicrosoftTrojan:Win32/Bunitucrypt.DE!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Bunitucrypt.C4892544
McAfeeArtemis!1677080C5094
MAXmalware (ai score=62)
VBA32Trojan.Qshell
MalwarebytesTrojan.Dropper
ZonerProbably Heur.RARAutorun
TrendMicro-HouseCallTROJ_GEN.R002C0DLQ21
TencentWin32.Trojan.Qshell.Dxwx
SentinelOneStatic AI – Suspicious PE
FortinetW32/Injector.EQUG!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Bunitucrypt.DE!MTB?

Trojan:Win32/Bunitucrypt.DE!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment