Trojan

TrojanDownloader:Win32/Unruy!pz malicious file

Malware Removal

The TrojanDownloader:Win32/Unruy!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Unruy!pz virus can do?

  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine TrojanDownloader:Win32/Unruy!pz?


File Info:

name: DC4541818C1A31349592.mlw
path: /opt/CAPEv2/storage/binaries/bb27156f48518d8294138224075eb052793558699a45f76ff159438a3b47c2fd
crc32: 570C64F9
md5: dc4541818c1a313495923b297674c0dc
sha1: 5489b848d7e3e73f80d99b8c52e8bf168765a8c4
sha256: bb27156f48518d8294138224075eb052793558699a45f76ff159438a3b47c2fd
sha512: 3bfa02e2037c7327e1bdee1c1254c901330ad3e0752f568a587415d5a72fab24877ed99390170ab2c7248bd9ae1be6d6f0f34537c89d50d13c6806eb09ed4f18
ssdeep: 98304:nGycOCGycO6GycOFGycOXGycOaGycOlGycOXGycO6GycOFGycOKGyaOaGyaOIGyG:GEcHl8nFcHkWMh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11426AE35403D1C63C3B9BC3CF245D4E151A102EA5AA71DCAEE59883A69F1D9C9B1E3CB
sha3_384: fb4ae534b5533918fd6613046d9eca68f68c3c83d62b776facdabfa244b5b44e1c430333d1f5fb1494c52dac48b064f2
ep_bytes: 558bec6aff6898dc4400688685440064
timestamp: 2010-06-09 10:32:16

Version Info:

0: [No Data]

TrojanDownloader:Win32/Unruy!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.ljdO
MicroWorld-eScanGen:Variant.Graftor.1398
FireEyeGeneric.mg.dc4541818c1a3134
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighDownloader-BZH.gen.a
ALYacGen:Variant.Graftor.1398
Cylanceunsafe
VIPREGen:Variant.Graftor.1398
SangforSuspicious.Win32.Save.ins
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Graftor.1398
BitDefenderThetaGen:NN.ZexaF.36792.@tW@ayniCubb
VirITTrojan.Win32.Agent.FQQ
SymantecW32.Unruy.A
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Unruy-5828
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanDownloader:Win32/Unruy.da0a09de
NANO-AntivirusTrojan.Win32.Renamer.lloxl
ViRobotBackdoor.Win32.A.Banito.679587
RisingBackdoor.Win32.Deflate.ag (CLASSIC)
EmsisoftGen:Variant.Graftor.1398 (B)
BaiduWin32.Backdoor.Gpigeon2010.a
F-SecureMalware.W32/Agent.EA
DrWebBackDoor.Bandito.2214
ZillyaDownloader.Unruy.Win32.2883
TrendMicroTROJ_UNRUY.SMKV
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
JiangminBackdoor/Banito.ags
WebrootW32.Trojan.Gen
AviraW32/Agent.EA
MAXmalware (ai score=84)
Antiy-AVLTrojan[Backdoor]/Win32.Banito
KingsoftWin32.AtInfect.lx.720668
MicrosoftTrojanDownloader:Win32/Unruy!pz
XcitiumTrojWare.Win32.Agent.QTV@4pnpwk
ArcabitTrojan.Graftor.D576
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.1W2RGEU
VaristW32/Backdoor.K.gen!Eldorado
McAfeeDownloader-BZH.gen.a
DeepInstinctMALICIOUS
VBA32BScope.Trojan.TE.01527
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UNRUY.SMKV
TencentTrojan.Win32.Banito.a
IkarusTrojan.Win32.Obfuscated
MaxSecureVirus.W32.Renamer.E
FortinetW32/Obfuscated.NEZ!tr
AVGWin32:Unruy-N [Trj]
Cybereasonmalicious.8d7e3e
AvastWin32:Unruy-N [Trj]

How to remove TrojanDownloader:Win32/Unruy!pz?

TrojanDownloader:Win32/Unruy!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment