Trojan

Should I remove “Trojan:Win32/BunituCrypt.RM!MTB”?

Malware Removal

The Trojan:Win32/BunituCrypt.RM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/BunituCrypt.RM!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
mas.to

How to determine Trojan:Win32/BunituCrypt.RM!MTB?


File Info:

crc32: 7BADC873
md5: 497130ee47253357e5ad3e0fc788e6d1
name: 497130EE47253357E5AD3E0FC788E6D1.mlw
sha1: d4c4868c46926717017eeac9e31f57971006017a
sha256: 0206979b4589e63a0fc346d65fb54b638ea9a580ee8d7db2184cebaa2ec120f8
sha512: 5b3b822dc18b74ee0f38eadb93a9bf8661a18eea28b91149d9f58a4c006b4fe5778d664921753e3af323e0c6e5c8cb2c1a6f6693f3f5dd6f466a88cabeeac106
ssdeep: 24576:iGFs/C0Ypl+AbITPp1y/44eI6rUg+gybEnlKoHFwbyrVo4euCyHXL+MQc3Pi:ivYfbIp1y9g1nl3lwbyC4RGI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/BunituCrypt.RM!MTB also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00589e171 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.31412
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.38010458
CylanceUnsafe
ZillyaTrojan.Injector.Win32.1273200
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/BunituCrypt.15928c8b
K7GWTrojan ( 00589e171 )
CyrenW32/DelfInject.EP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EPYR
APEXMalicious
AvastWin32:InjectorX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Injuke.gen
BitDefenderTrojan.GenericKD.38010458
ViRobotTrojan.Win32.Z.Injector.1623552.K
MicroWorld-eScanTrojan.GenericKD.38010458
TencentMalware.Win32.Gencirc.10cf8741
Ad-AwareTrojan.GenericKD.38010458
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZelphiCO.34266.JHW@aWpcTbfO
TrendMicroTROJ_GEN.R002C0WKE21
McAfee-GW-EditionBehavesLike.Win32.Fareit.tc
FireEyeGeneric.mg.497130ee47253357
EmsisoftTrojan.GenericKD.38010458 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.GenSteal.ielne
Antiy-AVLTrojan/Generic.ASMalwS.34CDD42
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/BunituCrypt.RM!MTB
GDataTrojan.GenericKD.38010458
AhnLab-V3Trojan/Win.Generic.C4769985
McAfeeGenericRXQS-HV!497130EE4725
MAXmalware (ai score=84)
VBA32TScope.Trojan.Delf
MalwarebytesSpyware.PasswordStealer
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0WKE21
RisingTrojan.Kryptik!1.D9CB (CLASSIC)
YandexTrojan.Injuke!RN0m3J012oo
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.FMWI!tr
AVGWin32:InjectorX-gen [Trj]

How to remove Trojan:Win32/BunituCrypt.RM!MTB?

Trojan:Win32/BunituCrypt.RM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment