Worm

Worm:Win32/Yuner!pz removal guide

Malware Removal

The Worm:Win32/Yuner!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Yuner!pz virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Attempts to identify installed AV products by registry key
  • Detects the presence of Windows Defender AV emulator via files
  • Attempts to disable System Restore
  • Attempts to disable Windows File Protection aka System File Checker.
  • Touches a file containing cookies, possibly for information gathering
  • Attempts to modify or disable Security Center warnings
  • Attempts to modify Explorer settings to prevent file extensions from being displayed
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Worm:Win32/Yuner!pz?


File Info:

name: 3873F8364F44D6913F9A.mlw
path: /opt/CAPEv2/storage/binaries/8ae357c63f21bf00a7def4c00f551760d18bd1ff81f2869dfd0cb9351c7237fa
crc32: 0A6F0544
md5: 3873f8364f44d6913f9a9d24c87c9966
sha1: 4385490a341605c460df30643d5c8c311513bce9
sha256: 8ae357c63f21bf00a7def4c00f551760d18bd1ff81f2869dfd0cb9351c7237fa
sha512: baf1c529a7e96e88e3e9e15d4dc1de913eef7a051972b1054d2b57187ebfb921a25580e26b56a7c08c12a9529dfe5bf5a392b20c6b0b01da8f738f26d188a70d
ssdeep: 6144:1VY0W0sVVZ/dkq5BCoFaJ2i5Lf24C07N5OvSLTUF6pQxI6Upe2cBnTu19bcodj6+:1gDhdkq5BCoC5LfWSLTUQpr2Zu19Qm5V
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CFB4AE2276E1B0B2E96325F00F76D728E777BC3456359447A7C02E8BAA30951973B363
sha3_384: 18f19e6d2e5b98dbd1fe2e4b8cc490ca146ec739e09b981fcbcbbc6b848f51e31b7807b2d3cd33c0b299ccb51a9bd38e
ep_bytes: e858b10000e917feffffb8abe44500a3
timestamp: 2007-09-10 14:57:50

Version Info:

FileDescription:
Virus.Name.: ., ., ., .
Nuyer.........: ...... .. ...... : ., ., ., .
Translation: 0x0809 0x04b0

Worm:Win32/Yuner!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanWorm.Hybris.PLI
CAT-QuickHealWorm.AutoIt.Yuner.A
SkyhighBehavesLike.Win32.Yahlover.hh
McAfeeArtemis!3873F8364F44
MalwarebytesYuner.Worm.Propagation.DDS
VIPREWorm.Hybris.PLI
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 005506171 )
BitDefenderWorm.Hybris.PLI
K7GWTrojan ( 005506171 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduAutoIt.Worm.Yuner.a
VirITWorm.Win32.Autoit.ZNM
SymantecW32.Badday.A
Elasticmalicious (high confidence)
ESET-NOD32Win32/Yuner.A
APEXMalicious
ClamAVWin.Worm.Autoit-6803981-0
KasperskyWorm.Win32.AutoRun.but
AlibabaWorm:Win32/Yuner.e43d9ade
NANO-AntivirusTrojan.Script.Agent.dbvlfz
ViRobotWorm.Win32.Autorun.524706
RisingTrojan.Win32.Autoit.edj (CLASSIC)
SophosW32/Sohana-CU
F-SecureTrojan.TR/AutoIt.SB
DrWebTrojan.AVKill.31317
ZillyaWorm.AutoRun.Win32.5414
TrendMicroWORM_AUTORUN.BVM
EmsisoftWorm.Hybris.PLI (B)
IkarusWorm.Win32.AutoRun
GDataWin32.Trojan.PSE.IXJIRB
JiangminTrojanDownloader.JS.hi
WebrootW32.Yuner.Gen
GoogleDetected
AviraTR/AutoIt.SB
VaristW32/A-91e93787!Eldorado
Antiy-AVLWorm/Win32.AutoRun
KingsoftWin32.HeurC.KVM007.a
XcitiumWorm.Win32.Yuner.B@533776
ArcabitWorm.Hybris.PLI
ZoneAlarmHEUR:Worm.Win32.Yuner.gen
MicrosoftWorm:Win32/Yuner!pz
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Hybris.R3751
BitDefenderThetaAI:Packer.44866B6B18
TACHYONWorm/W32.AutoRun.524706
DeepInstinctMALICIOUS
VBA32Trojan.Yuner.19105
Cylanceunsafe
PandaW32/Autorun.JFC.worm
ZonerWorm.Win32.22192
TrendMicro-HouseCallWORM_AUTORUN.BVM
TencentWorm.Win32.AutoRun.f
YandexWorm.Yuner!OOwCwIXRc+0
MaxSecureWorm.W32.AutoIT.R
FortinetW32/AutoRun.BUT!worm
AVGAutoIt:Dropper-D [Drp]
Cybereasonmalicious.a34160
AvastAutoIt:Dropper-D [Drp]

How to remove Worm:Win32/Yuner!pz?

Worm:Win32/Yuner!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment