Trojan

What is “TrojanDownloader:Win32/Unruy!pz”?

Malware Removal

The TrojanDownloader:Win32/Unruy!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Unruy!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses suspicious command line tools or Windows utilities

How to determine TrojanDownloader:Win32/Unruy!pz?


File Info:

name: 2C2B91ED487CC59BC65E.mlw
path: /opt/CAPEv2/storage/binaries/b6346e16e15e7cbec04acca45060b8364989df94064d01753a24899c71598239
crc32: D64941DB
md5: 2c2b91ed487cc59bc65e400ab0f4b47a
sha1: a7ff0b87c026e066e05ef6907b941c18e8e8160c
sha256: b6346e16e15e7cbec04acca45060b8364989df94064d01753a24899c71598239
sha512: ef174238d8bda87fd435305dd816ba7b383aa47b5b7e8dd9a339411b6f08b6403509bd0a3fd50bc5329c90606261aad86406b145edaf380a8cdc66487655c140
ssdeep: 6144:BhGUslB44d5nnjJgJFLkHdwbaGBNv4odFrDBi4G0gQiwJAro2Y4GzAUBXLVurnbz:Bhnsl64bkF4BB4UaJp04xmwu4hm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C7B4BF65D465AA3BE72BC93F899E3939871623F3BF43B5CB4421E5810971282EF0251F
sha3_384: c01c4800aea00dbb2421132d9bab53d9c9cb252a29e6b1427cb16b37a2120f0ff0aaec3b783ec86194cdc1f5588f93c1
ep_bytes: 558bec6aff68c880400068ac58400064
timestamp: 2009-12-11 21:31:37

Version Info:

0: [No Data]

TrojanDownloader:Win32/Unruy!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.433357
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.gm
McAfeeGenericRXRY-AY!2C2B91ED487C
Cylanceunsafe
SangforSuspicious.Win32.Save.ins
Cybereasonmalicious.d487cc
BaiduWin32.Trojan-Clicker.Cycler.a
SymantecW32.Unruy.A
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Unruy.AY
APEXMalicious
TrendMicro-HouseCallTROJ_UNRUY.SMT
ClamAVWin.Downloader.Unruy-6988793-0
KasperskyVHO:Trojan-Clicker.Win32.Cycler.gen
BitDefenderGen:Variant.Zusy.433357
NANO-AntivirusTrojan.Win32.GenKryptik.fnqhed
SUPERAntiSpywareTrojan.Agent/Gen-Unruy
AvastWin32:Unruy-AA [Trj]
TencentTrojan.Win32.Unruy.wa
EmsisoftGen:Variant.Zusy.433357 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLC.Asdas.22
VIPREGen:Variant.Zusy.433357
TrendMicroTROJ_UNRUY.SMT
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.2c2b91ed487cc59b
SophosTroj/DwnLdr-IFB
IkarusTrojan-Downloader.Win32.Unruy
JiangminTrojan.Generic.glpgv
WebrootW32.Trojan.Downloader.Unruy.Gen
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan[Downloader]/Win32.Unruy
MicrosoftTrojanDownloader:Win32/Unruy!pz
XcitiumTrojWare.Win32.TrojanSpy.BZub.~IP@f810f
ArcabitTrojan.Zusy.D69CCD
ZoneAlarmVHO:Trojan-Clicker.Win32.Cycler.gen
GDataWin32.Trojan.PSE.RSIYTE
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Unruy.C5579177
Acronissuspicious
VBA32Trojan.Azden
ALYacGen:Variant.Zusy.433357
MAXmalware (ai score=88)
MalwarebytesGeneric.Malware.AI.DDS
PandaGeneric Suspicious
RisingDownloader.Unruy!1.AE5E (CLASSIC)
YandexTrojan.GenAsa!S4Mv8DNs2+w
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/UNRUY.BK!tr
BitDefenderThetaGen:NN.ZexaF.36802.EqZ@aC8C@7h
AVGWin32:Unruy-AA [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan:Win/Unruy.A(dyn)

How to remove TrojanDownloader:Win32/Unruy!pz?

TrojanDownloader:Win32/Unruy!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment