Trojan

Should I remove “TrojanDownloader:Win32/Unruy!pz”?

Malware Removal

The TrojanDownloader:Win32/Unruy!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Unruy!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Uses suspicious command line tools or Windows utilities
  • Yara detections observed in process dumps, payloads or dropped files

How to determine TrojanDownloader:Win32/Unruy!pz?


File Info:

name: AE6BBB0BFDEDE2AC372B.mlw
path: /opt/CAPEv2/storage/binaries/39d69bd2e4ce45648263cda4ad64829f423d257265366de0cc181e54d30bc480
crc32: 1A0EFCD1
md5: ae6bbb0bfdede2ac372b09fdcd69e8f1
sha1: 4230e1ba97b1ed1d75a88d82f045ac28779d4eb4
sha256: 39d69bd2e4ce45648263cda4ad64829f423d257265366de0cc181e54d30bc480
sha512: 12b4357331710835e38cd09381bef59b59e3a2cae726f930b68b270c211632af9a52a819c4699f6836ffa542f1d318510052f2a4b86f611f9dd00b315d38a72e
ssdeep: 6144:LMSUslh44d5nnnQFZJ6R7dckZ9wTxA0VCrKj0dHfEK3O7455zuIA5kF6HRgjA1VO:LMLsla4bnLmAp33zYDLnVBdssa
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T128B4BF61D865563BE32BD93B59AA3F39862D33B7BA43F5CB9415D1C904A6282FF0100F
sha3_384: 1665c3b3defe9f6a508f0236e2b659ba6f6ccdfc252848790ffaa19222180facf250e1960543b53ea2c536a5669f03f7
ep_bytes: 558bec6aff68c880400068ac58400064
timestamp: 2009-12-11 21:31:37

Version Info:

0: [No Data]

TrojanDownloader:Win32/Unruy!pz also known as:

BkavW32.AIDetectMalware
AVGWin32:Unruy-AA [Trj]
tehtrisGeneric.Malware
DrWebWin32.HLLC.Asdas.22
MicroWorld-eScanGen:Variant.Zusy.433357
FireEyeGeneric.mg.ae6bbb0bfdede2ac
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Downloader.gm
McAfeeGenericRXRY-AY!AE6BBB0BFDED
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDownloader.Unruy.Win32.7564
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan-Downloader ( 001156081 )
K7GWTrojan-Downloader ( 001156081 )
Cybereasonmalicious.a97b1e
BitDefenderThetaGen:NN.ZexaF.36744.EqZ@auwGjlc
SymantecW32.Unruy.A
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Unruy.AY
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:Unruy-AA [Trj]
ClamAVWin.Downloader.Unruy-6988793-0
KasperskyHEUR:Trojan-Clicker.Win32.Cycler.pef
BitDefenderGen:Variant.Zusy.433357
NANO-AntivirusTrojan.Win32.GenKryptik.fnqhed
SUPERAntiSpywareTrojan.Agent/Gen-Unruy
TencentTrojan.Win32.Unruy.wa
EmsisoftGen:Variant.Zusy.433357 (B)
F-SecureTrojan.TR/Dropper.Gen
BaiduWin32.Trojan-Clicker.Cycler.a
VIPREGen:Variant.Zusy.433357
TrendMicroTROJ_UNRUY.SMT
Trapminemalicious.high.ml.score
SophosTroj/Cycler-C
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.glpgv
WebrootW32.Trojan.Downloader.Unruy.Gen
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=84)
Antiy-AVLTrojan[Downloader]/Win32.Unruy
MicrosoftTrojanDownloader:Win32/Unruy!pz
XcitiumTrojWare.Win32.TrojanSpy.BZub.~IP@f810f
ArcabitTrojan.Zusy.D69CCD
ZoneAlarmHEUR:Trojan-Clicker.Win32.Cycler.pef
GDataWin32.Trojan.PSE.RSIYTE
VaristW32/Unruy.S.gen!Eldorado
Acronissuspicious
ALYacGen:Variant.Zusy.433357
VBA32Trojan.Azden
Cylanceunsafe
PandaGeneric Suspicious
TrendMicro-HouseCallTROJ_UNRUY.SMT
RisingDownloader.Unruy!1.AE5E (CLASSIC)
YandexTrojan.GenAsa!S4Mv8DNs2+w
IkarusTrojan-Downloader.Win32.Unruy
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/UNRUY.BK!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove TrojanDownloader:Win32/Unruy!pz?

TrojanDownloader:Win32/Unruy!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment