Malware

PWS:Win32/Yunsip!pz removal guide

Malware Removal

The PWS:Win32/Yunsip!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Yunsip!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine PWS:Win32/Yunsip!pz?


File Info:

name: 3F671ABD7C46023AEEB3.mlw
path: /opt/CAPEv2/storage/binaries/76b85aebba18e3c53375f270d0f1f6916de9ff8e4e44a812637db165b451da67
crc32: F987786C
md5: 3f671abd7c46023aeeb38f5cf0126f93
sha1: b80b7d0b206427d40a5fb5178d06a00e88091a06
sha256: 76b85aebba18e3c53375f270d0f1f6916de9ff8e4e44a812637db165b451da67
sha512: 7bd216885dac23df352c2a5f621a9f2efa7428b01f3677176c12e10721e65eeb6bce48a71e7b122f8761b229901ab6f1fe8ca0e91487851eeb3a9138de8ad3c6
ssdeep: 3072:cDJpt9sSR0HUHPwZWLnWUfEAzV2IJIwTBftpmc+z+f3Q0M:cDHtfRQUHPw0TMoV2nwTBlhm8U
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1DA0591026AD470AAF597053E0AA4B7B7FE6A6DB1BCD84A470207DECCD431D07B6D0E46
sha3_384: bfbdb68474b1ac4468e64c52f98e5e152b8ee23a2d377bce77a7894d8c843165ed6f13003183db581677dc0634610169
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2011-06-09 14:27:31

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Uniscribe Unicode script processor
FileVersion: 1.0420.2600.5512 (xpsp.080413-2105)
InternalName: Uniscribe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: Uniscribe
ProductName: Microsoft(R) Uniscribe Unicode script processor
ProductVersion: 1.0420.2600.5512
Translation: 0x0409 0x04b0

PWS:Win32/Yunsip!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Doina.1084
FireEyeGeneric.mg.3f671abd7c46023a
CAT-QuickHealTrojan.MauvaiseRI.S5242729
SkyhighBehavesLike.Win32.PWSYunsip.cz
McAfeePWS-Yunsip.gen.a
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Doina.1084
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan ( 005514aa1 )
BitDefenderGen:Variant.Doina.1084
K7GWTrojan ( 005514aa1 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Trojan-Spy.Agent.aa
VirITTrojan.Win32.Agent.ANTV
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Agent.NWL
APEXMalicious
ClamAVWin.Trojan.Agent-1366997
KasperskyHEUR:Backdoor.Win32.Generic
NANO-AntivirusTrojan.Win32.Agent.rgzka
SophosML/PE-A
F-SecureTrojan.TR/PSW.Yunsip.axyza
DrWebTrojan.PWS.Spy.20716
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Doina.1084 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=86)
GDataWin32.Trojan-Stealer.Yunsip.B
JiangminBackdoor.Generic.bhxd
GoogleDetected
AviraTR/PSW.Yunsip.axyza
VaristW32/Redosdru.B.gen!Eldorado
Antiy-AVLTrojan/Win32.Agent.uwue
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.TrojanSpy.Agent.ny@4pn6tf
ArcabitTrojan.Doina.D43C
ZoneAlarmHEUR:Backdoor.Win32.Generic
MicrosoftPWS:Win32/Yunsip!pz
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Infostealer.R758
Acronissuspicious
BitDefenderThetaGen:NN.ZedlaF.36802.Zy@@a08BqAbi
ALYacGen:Variant.Doina.1084
TACHYONWorm/W32.Yunsip.Zen
DeepInstinctMALICIOUS
VBA32TScope.Malware-Cryptor.SB
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Usp10Hijack!1.998B (CLASSIC)
YandexTrojan.GenAsa!LogooVIKaNc
IkarusTrojan.Spy.Agent
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.NYB!tr
AVGWin32:Yunsip-A [Wrm]
AvastWin32:Yunsip-A [Wrm]
alibabacloudTrojan:Win/Zusy

How to remove PWS:Win32/Yunsip!pz?

PWS:Win32/Yunsip!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment