Trojan

TrojanDownloader:Win32/Unruy!pz removal instruction

Malware Removal

The TrojanDownloader:Win32/Unruy!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Unruy!pz virus can do?

  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)

How to determine TrojanDownloader:Win32/Unruy!pz?


File Info:

name: CB66EE3FB55F62BC086C.mlw
path: /opt/CAPEv2/storage/binaries/fbd50d77f24abdda59f039e3152a9ded86cc9b1e921a3d692e416b761faf9162
crc32: E9D56CA3
md5: cb66ee3fb55f62bc086c903a5fa3a85c
sha1: dd46fe9c9709c59007c6e3c8639be59776111a74
sha256: fbd50d77f24abdda59f039e3152a9ded86cc9b1e921a3d692e416b761faf9162
sha512: 9ce6f8c4296bae8606fcbcb77948232977b6b603d9c0fcf1887a92a518a362680f8da216d30cc3a42941b87726bb182787b4dc0eb710b4bdd21662ef5cecc261
ssdeep: 768:edIZ/alwuAknNWuCMQpb0ruFm1YqTrmHwbLyMyH:edILlknNU4rOobbLynH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16803BF0F3FE18013D5F956F463F25060E96742050D5F6A0E0B968538909A4FBEFF2A4A
sha3_384: 7ce494aecae559b33c56fa25ce3edd4097473053278be222ccdf0f8e493d2290fc29e6f9ab5344c3a6479417f23a093b
ep_bytes: 5668c2010000685c03000068ce000000
timestamp: 2011-01-21 14:08:50

Version Info:

0: [No Data]

TrojanDownloader:Win32/Unruy!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Powp.lmDC
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ProcessHijack.cqX@aeFAahi
ClamAVWin.Trojan.Powp-41
FireEyeGeneric.mg.cb66ee3fb55f62bc
CAT-QuickHealTrojanDownloader.Unruy.H
SkyhighDownloader-BPA.g
ALYacGen:Trojan.ProcessHijack.cqX@aeFAahi
Cylanceunsafe
ZillyaDownloader.Unruy.Win32.5822
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaVirTool:Win32/CeeInject.f0bc7a40
K7GWTrojan ( 003d7b911 )
K7AntiVirusTrojan ( 003d7b911 )
BitDefenderThetaAI:Packer.A4BF00891E
VirITTrojan.Win32.Crypt.AFMF
SymantecDownloader
ESET-NOD32Win32/TrojanDownloader.Unruy.BN
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.ProcessHijack.cqX@aeFAahi
NANO-AntivirusTrojan.Win32.Kazy.ikkvd
SUPERAntiSpywareTrojan.Agent/Gen-Virut
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10b33c49
TACHYONTrojan/W32.Powp.37912.C
SophosMal/EncPk-ZC
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLC.Asdas.7
VIPREGen:Trojan.ProcessHijack.cqX@aeFAahi
TrendMicroTSPY_DOWNLOADER_BK082F6F.TOMC
Trapminemalicious.high.ml.score
EmsisoftGen:Trojan.ProcessHijack.cqX@aeFAahi (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Powp.abr
WebrootW32.Trojan.Powp
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.Powp
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDownloader:Win32/Unruy!pz
XcitiumTrojWare.Win32.Powp.Gen2@2ma5ww
ArcabitTrojan.ProcessHijack.EC6D75
ViRobotTrojan.Win32.A.Powp.37904
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Trojan.ProcessHijack.cqX@aeFAahi
VaristW32/Trojan.GRIS-0327
AhnLab-V3Win-Trojan/Unruy.37980
McAfeeDownloader-BPA.g
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.Fareit
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Powp.I
ZonerTrojan.Win32.32694
TrendMicro-HouseCallTSPY_DOWNLOADER_BK082F6F.TOMC
RisingTrojan.Win32.DLoader.b (CLASSIC)
YandexTrojan.DL.Unruy!o3aD1XL5/7U
IkarusTrojan-Downloader.Win32.Unruy
FortinetW32/Powp.gen!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove TrojanDownloader:Win32/Unruy!pz?

TrojanDownloader:Win32/Unruy!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment