Home Malware Programs Trojans Trojan.Spy.Ursnif.gen!M

Trojan.Spy.Ursnif.gen!M

Posted: April 17, 2013

Threat Metric

Ranking: 14,722
Threat Level: 8/10
Infected PCs: 2,159
First Seen: April 17, 2013
Last Seen: October 8, 2023
OS(es) Affected: Windows

Aliases

Dropper.Generic8.WKA [AVG]Trojan-PWS.Win32.Zbot [Ikarus]Heuristic.LooksLike.Win32.Suspicious.C!81 [McAfee-GW-Edition]Trojan.Packed.24217 [DrWeb]Troj/Zbot-EPN [Sophos]Artemis!E86D4219C965 [McAfee]Heuristic.LooksLike.Win32.Suspicious.N [McAfee-GW-Edition]Artemis!831B77B37510 [McAfee]Suspicion: unknown virus [AVG]Worm.Win32.VBNA [Ikarus]Trojan.Win32.Agent.xjth [Kaspersky]W32/VB-Wird-based!Maximus [F-Prot]Virus.Win32.Heur [Ikarus]Trojan-Dropper.Win32.Clons.xvg [Kaspersky]Artemis!C5D3F6ECF6CB [McAfee]
More aliases (293)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%ALLUSERSPROFILE%\Lld6t51i.exe File name: Lld6t51i.exe
Size: 178.68 KB (178688 bytes)
MD5: 6e512dbe26061acab9b7860cd8696b9e
Detection count: 85
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: April 22, 2013
%SystemDrive%\RECYCLER\S-1-5-21-1220945662-57989841-1801674531-1003\$a7dfecf624a7f7e34aa05b67d1143ee0\n. File name: n.
Size: 49.66 KB (49664 bytes)
MD5: cd9a183e162d1cf5940fc1ddde34b66e
Detection count: 47
Path: %SystemDrive%\RECYCLER\S-1-5-21-1220945662-57989841-1801674531-1003\$a7dfecf624a7f7e34aa05b67d1143ee0
Group: Malware file
Last Updated: April 22, 2013
%SystemDrive%\Users\<username>\AppData\Local\KiXtart\nuqwsaqp.dll File name: nuqwsaqp.dll
Size: 747 KB (747008 bytes)
MD5: c5d3f6ecf6cb264be666710546f5b900
Detection count: 44
File type: Dynamic link library
Mime Type: unknown/dll
Path: %SystemDrive%\Users\<username>\AppData\Local\KiXtart
Group: Malware file
Last Updated: April 22, 2013
%LOCALAPPDATA%\Cisco\mqdaylns.dll File name: mqdaylns.dll
Size: 763.39 KB (763392 bytes)
MD5: f32b6dfe252f34737c78dd5b85711e1d
Detection count: 34
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\Cisco
Group: Malware file
Last Updated: April 22, 2013
%LOCALAPPDATA%\Lollipop\Lollipop.exe File name: Lollipop.exe
Size: 1.94 MB (1945088 bytes)
MD5: bffc70e77e3433cb559d674424b596b8
Detection count: 32
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Lollipop
Group: Malware file
Last Updated: April 22, 2013
%WINDIR%\IEXPLORER.EXE File name: IEXPLORER.EXE
Size: 233.47 KB (233472 bytes)
MD5: 52cad126f22f58d6406824b372b45985
Detection count: 23
File type: Executable File
Mime Type: unknown/EXE
Path: %WINDIR%
Group: Malware file
Last Updated: April 22, 2013
%WINDIR%\system32\dxps2bin.exe File name: dxps2bin.exe
Size: 220.16 KB (220160 bytes)
MD5: e86d4219c9656385f88c7b17f376e5af
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: April 29, 2013
%LOCALAPPDATA%\lollipop\lollipop_04162355.exe File name: lollipop_04162355.exe
Size: 2.11 MB (2117120 bytes)
MD5: a09c18fab5b82583b24180cd1cd6d18f
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\lollipop
Group: Malware file
Last Updated: April 22, 2013
%APPDATA%\Media Center Programs\WIND75B.exe File name: WIND75B.exe
Size: 139.26 KB (139264 bytes)
MD5: 74941bb93ed4fb90f3c4c8371235cb37
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Media Center Programs
Group: Malware file
Last Updated: April 22, 2013
%USERPROFILE%\configura??es locais\dados de aplicativos\lollipop\lollipop_04121305.exe File name: lollipop_04121305.exe
Size: 2.42 MB (2425856 bytes)
MD5: fb234b2d700d7514256bda23cebcdeee
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\configura??es locais\dados de aplicativos\lollipop
Group: Malware file
Last Updated: April 22, 2013
%USERPROFILE%\Downloads\libreoffice.exe File name: libreoffice.exe
Size: 1.6 MB (1607760 bytes)
MD5: 3f272c9b675d4c8f2899b8e428fb53c9
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Downloads
Group: Malware file
Last Updated: April 22, 2013
C:\Users\<username>\AppData\Roaming\BF1B.exe File name: BF1B.exe
Size: 100.4 KB (100404 bytes)
MD5: 1e512db447baf8d6c473f1bf8299c1fc
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Roaming\BF1B.exe
Group: Malware file
Last Updated: March 15, 2022
%APPDATA%\Leadertech\WIN46.exe File name: WIN46.exe
Size: 121.34 KB (121344 bytes)
MD5: 3db64454a9c1e5e458ed693c04daad35
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Leadertech
Group: Malware file
Last Updated: April 22, 2013
%WINDIR%\system32\diskhare.exe File name: diskhare.exe
Size: 212.48 KB (212480 bytes)
MD5: 0ded9f21b9878092048bbf6161914b42
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: April 17, 2013
%TEMP%\pkg_3e312610\bitzipper2.exe File name: bitzipper2.exe
Size: 1.6 MB (1607760 bytes)
MD5: 1b7f04d4ef9062f73794f70e0feeb6a7
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\pkg_3e312610
Group: Malware file
Last Updated: April 22, 2013
%LOCALAPPDATA%\Lollipop\Lollipop.exe File name: Lollipop.exe
Size: 2.42 MB (2420224 bytes)
MD5: f8716fa03f2ee3793898bdb6bcfa25d8
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\Lollipop
Group: Malware file
Last Updated: April 22, 2013
%LOCALAPPDATA%\lollipop\lollipop_04121712.exe File name: lollipop_04121712.exe
Size: 2.03 MB (2036736 bytes)
MD5: c783bad8907f4fa331683987e3e8c9fc
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\lollipop
Group: Malware file
Last Updated: April 22, 2013
%LOCALAPPDATA%\lollipop\lollipop_04132226.exe File name: lollipop_04132226.exe
Size: 1.56 MB (1565696 bytes)
MD5: f7b90948435b3c1a878274247ae503da
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\lollipop
Group: Malware file
Last Updated: April 22, 2013
%USERPROFILE%\System.exe File name: System.exe
Size: 103.42 KB (103424 bytes)
MD5: b82b2e7381516e3205f0955171bec8ae
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: April 22, 2013
%USERPROFILE%\8476709.exe File name: 8476709.exe
Size: 98.3 KB (98304 bytes)
MD5: 162b62eaeafdda5c6632fe8d943dd985
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: April 22, 2013
%APPDATA%\ftbafirg\cavdjgaa.exe File name: cavdjgaa.exe
Size: 184.12 KB (184128 bytes)
MD5: 4f79c51927599f75b1257e4e6696d669
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\ftbafirg
Group: Malware file
Last Updated: April 22, 2013
%ALLUSERSPROFILE%\System\00b06067.exe File name: 00b06067.exe
Size: 579.56 KB (579564 bytes)
MD5: 42068b5b08553164fefd1481824320bc
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\System
Group: Malware file
Last Updated: April 22, 2013
%APPDATA%\djtfgajw\tvejjevt.exe File name: tvejjevt.exe
Size: 45.05 KB (45056 bytes)
MD5: a47db361c48a2c5df85769a8b1ed81d3
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\djtfgajw
Group: Malware file
Last Updated: April 22, 2013

More files
Loading...