Malware

PWS:Win32/Yunsip.A removal

Malware Removal

The PWS:Win32/Yunsip.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Yunsip.A virus can do?

  • Creates RWX memory
  • Network activity detected but not expressed in API logs

How to determine PWS:Win32/Yunsip.A?


File Info:

crc32: DD0E0DDC
md5: 6baa02ace14e508b7df181df3043e8cf
name: 6BAA02ACE14E508B7DF181DF3043E8CF.mlw
sha1: 7eb0937bac85f15ab270379fa7c1b5a0dbf2a5fc
sha256: 5295bcbbb3f9953e42ce7fba08b95f0c99defda0a17737aca80acac05df76d34
sha512: d25fb43923d420b9f68147612b3d77192921e2671f68b6a7bee78f4200766eb32b171915762035b7b94b078e93163c64dde8cc72d2ea06ac907d06c1b087acfc
ssdeep: 3072:j9eIuMO5gi/10UtBDnX2iY5e9RXwTBftrm2YedGf3QKZDn:j9bG5N/eoXnY5enwTBlrIckP9
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: Uniscribe
FileVersion: 1.0420.2600.5512 (xpsp.080413-2105)
CompanyName: Microsoft Corporation
ProductName: Microsoft(R) Uniscribe Unicode script processor
ProductVersion: 1.0420.2600.5512
FileDescription: Uniscribe Unicode script processor
OriginalFilename: Uniscribe
Translation: 0x0409 0x04b0

PWS:Win32/Yunsip.A also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.319665
FireEyeGeneric.mg.6baa02ace14e508b
CAT-QuickHealTrojanPWS.Yunsip.A5
ALYacGen:Variant.Zusy.319665
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 00060f0b1 )
K7AntiVirusTrojan ( 00060f0b1 )
BaiduWin32.Trojan-Spy.Agent.aa
CyrenW32/Redosdru.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyHEUR:Backdoor.Win32.Generic
BitDefenderGen:Variant.Zusy.319665
ViRobotTrojan.Win32.Agent.131072.BJ
TencentTrojan.Win32.FakeMS.tpd
Ad-AwareGen:Variant.Zusy.319665
SophosMal/YunSip-A
F-SecureTrojan.TR/PSW.Yunsip.axyza
InvinceaML/PE-A + Mal/YunSip-A
McAfee-GW-EditionBehavesLike.Win32.PWSYunsip.gz
EmsisoftGen:Variant.Zusy.319665 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Generic.bhxd
AviraTR/PSW.Yunsip.axyza
MicrosoftPWS:Win32/Yunsip.A
ArcabitTrojan.Zusy.D4E0B1
ZoneAlarmHEUR:Backdoor.Win32.Generic
GDataWin32.Trojan-Stealer.Yunsip.A
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Infostealer.R758
Acronissuspicious
McAfeePWS-Yunsip.gen.a
MAXmalware (ai score=89)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesSpyware.PasswordStealer
PandaGeneric Suspicious
ESET-NOD32a variant of Win32/Agent.NWL
TrendMicro-HouseCallWORM_YUNSIP.SMR
RisingTrojan.Hijcusp!1.998B (CLASSIC)
YandexTrojan.GenAsa!LogooVIKaNc
IkarusBackdoor.Win32.Inject
FortinetW32/Agent.NYB!tr
BitDefenderThetaGen:NN.ZedlaF.34634.Au@@a05rPXji
AVGWin32:Yunsip-A [Wrm]
Qihoo-360Trojan.Win32.FakeUsp.E

How to remove PWS:Win32/Yunsip.A?

PWS:Win32/Yunsip.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment