Home Malware Programs Trojans Spy.Ursnif.gen!F

Spy.Ursnif.gen!F

Posted: December 1, 2010

Threat Metric

Threat Level: 8/10
Infected PCs: 220
First Seen: December 1, 2010
OS(es) Affected: Windows

Aliases

Dropper.Generic5.LUZ [AVG]W32/Injector.ARWW!tr [Fortinet]Trojan-Spy.Win32.Zbot [Ikarus]TR/Crypt.ULPM.Gen [AntiVir]Trojan-Dropper.Win32.Injector.arww [Kaspersky]Artemis!580DA17D6B4C [McAfee]TrojanDropper.Injector.arww [CAT-QuickHeal]Trj/Dtcontx.C [Panda]Win32/Cryptor [AVG]Mal/Generic-S [Sophos]TR/Spy.ZBot.2442245 [AntiVir]PWS-Zbot-FAQC!33ED990333CE [McAfee]Trj/Genetic.gen [Panda]Generic29.KYB [AVG]W32/Kryptik.AJOS [Fortinet]
More aliases (156)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%USERPROFILE%\nah_kttn.exe File name: nah_kttn.exe
Size: 235 KB (235008 bytes)
MD5: 580da17d6b4c1478caf054b136aeb703
Detection count: 126
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: March 29, 2013
%USERPROFILE%\nah_plrf.exe File name: nah_plrf.exe
Size: 76.8 KB (76800 bytes)
MD5: 429aa6776d14e811b31c30a8dfefae94
Detection count: 84
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: December 7, 2010
%USERPROFILE%\govqler.exe File name: govqler.exe
Size: 155.64 KB (155648 bytes)
MD5: e1baf85614222d3a1c3ac14e1592562b
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: September 26, 2012
%USERPROFILE%\nah_rdds.exe File name: nah_rdds.exe
Size: 75.26 KB (75264 bytes)
MD5: 775a45f299fbd5487c3a85e96f0e1344
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: December 1, 2010
%USERPROFILE%\nah_aqkx.exe File name: nah_aqkx.exe
Size: 209.4 KB (209408 bytes)
MD5: 4018479476023f96957dcdeb5d4296f9
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: January 16, 2012
%USERPROFILE%\govcpeu.exe File name: govcpeu.exe
Size: 144.89 KB (144896 bytes)
MD5: 851d9373657b5d395844591a7084332a
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: March 21, 2013
%USERPROFILE%\govaplm.exe File name: govaplm.exe
Size: 160.76 KB (160768 bytes)
MD5: 33ed990333ce85180012ca993cdabf21
Detection count: 3
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: March 21, 2013
Loading...