Trojan

TrojanDownloader:Win32/Unruy!pz removal instruction

Malware Removal

The TrojanDownloader:Win32/Unruy!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Unruy!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Touches a file containing cookies, possibly for information gathering
  • Uses suspicious command line tools or Windows utilities

How to determine TrojanDownloader:Win32/Unruy!pz?


File Info:

name: 268864FF5C394729EBE9.mlw
path: /opt/CAPEv2/storage/binaries/8b77d999084aa8b830b437e96304aaa5d5881dfe8de2e37f9667088b637ba0f1
crc32: BB42B4BE
md5: 268864ff5c394729ebe9dc5e177ab6f3
sha1: 9cbd7ef1b3c1dff09006bc0d64725062df9d710d
sha256: 8b77d999084aa8b830b437e96304aaa5d5881dfe8de2e37f9667088b637ba0f1
sha512: 033336bfe91584f5b04a4cf806e8c27f10b1b0ae6604299e7fe244bd636bb586b7868fe87e4666a1f9957b1894065f3729415167299c21c0742b48d561a00a71
ssdeep: 12288:NNnsl64bdF4BB4UaJp04xmwu4h+QvaTsVbp:NNh4boaXpP98UV9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T116C4B0A4D5656B3BE32BC93B899E3D398B1523F3BB43B18B4425E58515722D2EF0210F
sha3_384: ef88ee1d3a82684f5dba5f2c9d90199c67d5915a6068850adc6973c61c81e32cf64ba7eceb3d98b87d1d5f790c1f526c
ep_bytes: 558bec6aff68c880400068ac58400064
timestamp: 2009-12-11 21:31:37

Version Info:

0: [No Data]

TrojanDownloader:Win32/Unruy!pz also known as:

BkavW32.AIDetectMalware
AVGWin32:Unruy-AA [Trj]
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zusy.433357
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.hm
McAfeeGenericRXMN-SQ!268864FF5C39
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDownloader.Unruy.Win32.7671
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan-Downloader ( 001156081 )
K7GWTrojan-Downloader ( 001156081 )
Cybereasonmalicious.f5c394
BaiduWin32.Trojan-Clicker.Cycler.a
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Unruy.AY
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Downloader.Unruy-6988793-0
KasperskyHEUR:Trojan-Clicker.Win32.Cycler.gen
BitDefenderGen:Variant.Zusy.433357
NANO-AntivirusTrojan.Win32.GenKryptik.fnqhed
SUPERAntiSpywareTrojan.Agent/Gen-Unruy
AvastWin32:Unruy-AA [Trj]
TencentTrojan.Win32.Unruy.wa
EmsisoftGen:Variant.Zusy.433357 (B)
F-SecureTrojan.TR/Dropper.Gen
DrWebWin32.HLLC.Asdas.22
VIPREGen:Variant.Zusy.433357
TrendMicroTROJ_UNRUY.SMT
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.268864ff5c394729
SophosTroj/Cycler-C
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.glpgv
VaristW32/Unruy.U.gen!Eldorado
AviraTR/Dropper.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan[Clicker]/Win32.Cycler
Kingsoftmalware.kb.a.1000
MicrosoftTrojanDownloader:Win32/Unruy!pz
XcitiumTrojWare.Win32.TrojanSpy.BZub.~IP@f810f
ArcabitTrojan.Zusy.D69CCD
ZoneAlarmHEUR:Trojan-Clicker.Win32.Cycler.gen
GDataWin32.Trojan.PSE.RSIYTE
GoogleDetected
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36802.HqZ@aC8C@7h
VBA32Trojan.Azden
Cylanceunsafe
PandaGeneric Suspicious
TrendMicro-HouseCallTROJ_UNRUY.SMT
RisingDownloader.Unruy!1.AE5E (CLASSIC)
YandexTrojan.GenAsa!S4Mv8DNs2+w
IkarusTrojan-Downloader.Win32.Unruy
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/UNRUY.BK!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan:Win/Unruy.A(dyn)

How to remove TrojanDownloader:Win32/Unruy!pz?

TrojanDownloader:Win32/Unruy!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment