Home Malware Programs Trojans TrojanProxy:Win32/Bunitu.F

TrojanProxy:Win32/Bunitu.F

Posted: December 1, 2014

Threat Metric

Threat Level: 9/10
Infected PCs: 110
First Seen: December 1, 2014
Last Seen: October 18, 2020
OS(es) Affected: Windows

TrojanProxy:Win32/Bunitu.F is a Trojan that has many traits for performing random unwanted actions on a PC. The TrojanProxy:Win32/Bunitu.F threat may come malicious sources on the Internet. TrojanProxy:Win32/Bunitu.F is prone to running in the background where it could allow a remote attacker to gain access to the infected computer without any indication to the computer user. TrojanProxy:Win32/Bunitu.F may lead to serious issues where data stored on the infected system is compromised. It is crucial to detect and remove TrojanProxy:Win32/Bunitu.F promptly through the use of a trusted antispyware tool that has the capability to locate safely and eliminate Trojan threats on a PC.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



1toman.exe File name: 1toman.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
1erree.exe File name: 1erree.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
1bovtensdf.exe File name: 1bovtensdf.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
1oiran.exe File name: 1oiran.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
msiexec.exe File name: msiexec.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
7.exe File name: 7.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
6.exe File name: 6.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
5.exe File name: 5.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
bilmopc.dll File name: bilmopc.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
lanh32.dll File name: lanh32.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
pdafoir.dll File name: pdafoir.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
topruwj.dll File name: topruwj.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
zunktir.dll File name: zunktir.dll
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
itcoe.sys File name: itcoe.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
itcom.sys File name: itcom.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
krnllds.sys File name: krnllds.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
nvmapi.sys File name: nvmapi.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
nvnapi.sys File name: nvnapi.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
nvnati.sys File name: nvnati.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
nvnatv.sys File name: nvnatv.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file
sha1krnl.sys File name: sha1krnl.sys
File type: System file
Mime Type: unknown/sys
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ccPxySvcHKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ccPwdSvcHKEY_LOCAL_MACHINE \SYSTEM\CurrentControlSet\Services\NISUMHKEY_LOCAL_MACHINE \SYSTEM\CurrentControlSet\Services\SymEventHKEY_LOCAL_MACHINE \SYSTEM\CurrentControlSet\Services\SYMTDIHKEY_LOCAL_MACHINE \SYSTEM\CurrentControlSet\Services\VFILT
Loading...