TROJ_BUNITU.QUE
Trojan horse Proxy.BCDZ (AVG), Trojan-Proxy.BCDZ (Ikarus), TrojanProxy:Win32/Bunitu.F (Microsoft), a variant of Win32/TrojanProxy.Agent.NVE trojan (NOD32)
Windows 2000, Windows Server 2003, Windows XP (32-bit, 64-bit), Windows Vista (32-bit, 64-bit), Windows 7 (32-bit, 64-bit)

Threat Type: Trojan
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It requires its main component to successfully perform its intended routine.
TECHNICAL DETAILS
Arrival Details
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Other System Modifications
This Trojan creates the following registry entry(ies) to bypass Windows Firewall:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\SharedAccess\Parameters\
FirewallPolicy\StandardProfile\AuthorizedApplications\
List
{Malware Path and File name} = "{Malware Path and File name}:*:Enabled:{File Name}"
Other Details
This Trojan connects to the following possibly malicious URL:
- ns1.{BLOCKED}clop.com
It requires its main component to successfully perform its intended routine.