Home Malware Programs Backdoors Backdoor.Ursap!rts

Backdoor.Ursap!rts

Posted: September 5, 2011

Threat Metric

Threat Level: 6/10
Infected PCs: 391
First Seen: December 1, 2010
Last Seen: January 17, 2021
OS(es) Affected: Windows

Backdoor.Ursap!rts is a malicious backdoor Trojan that is able to access a targeted computer system without a PC user's knowledge, and can download and install additional mhttp://www.spywareremove.com/wp-admin/post.php?post=210351&action=edit#alware threats. Once Backdoor.Ursap!rts is installed onto the infected PC, attackers are able to obtain remote access to the computer system and steal all the computer user's sensitive data, such as banking details and passwords. Backdoor.Ursap!rts can disable the firewall and delete or change registry entries and other essential PC system settings. Delete Backdoor.Ursap!rts from the corrupted machine by using a reliable anti-virus application.

Aliases

BackDoor.Generic_r.LG [AVG]W32/Jorik_Lolbot.AOP!tr [Fortinet]Heuristic.LooksLike.Win32.Suspicious.F [McAfee-GW-Edition]TR/Spy.907776.5 [AntiVir]Trojan.DownLoader6.12833 [DrWeb]Trojan.Generic.KDV.696237 [BitDefender]Trojan.Win32.Jorik.Lolbot.aop [Kaspersky]Win32.Fakealert.Sesh [eSafe]Generic BackDoor!fq3 [McAfee]Trojan.Jorik.Lolbot.aop [CAT-QuickHeal]Trj/OCJ.A [Panda]Generic30.AFJ [AVG]W32/VB.BXSP!tr [Fortinet]Dropper/Win32.VB [AhnLab-V3]TR/StartPage.ald.1 [AntiVir]
More aliases (371)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%COMMONPROGRAMFILES%\MediaCatalogMergedDB\MediaCatalogMergedDBProvider.exe File name: MediaCatalogMergedDBProvider.exe
Size: 41.56 KB (41568 bytes)
MD5: 0240316967cadee54a6f345fea1d27cf
Detection count: 74
File type: Executable File
Mime Type: unknown/exe
Path: %COMMONPROGRAMFILES%\MediaCatalogMergedDB
Group: Malware file
Last Updated: July 23, 2012
%WINDIR%\system32\install\server.exe File name: server.exe
Size: 705.1 KB (705101 bytes)
MD5: 8110abff754d48cee6d666d26c8173c0
Detection count: 71
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\install
Group: Malware file
Last Updated: November 19, 2012
%COMMONPROGRAMFILES%\MSSecurity\wscntfy.exe File name: wscntfy.exe
Size: 40.96 KB (40960 bytes)
MD5: 491d9c472a82a92ecbb22470814cec63
Detection count: 37
File type: Executable File
Mime Type: unknown/exe
Path: %COMMONPROGRAMFILES%\MSSecurity
Group: Malware file
Last Updated: June 21, 2011
%USERPROFILE%\wsnKBD.exe File name: wsnKBD.exe
Size: 198.65 KB (198656 bytes)
MD5: 7581b628c7c8de3c632158d505cbb8f5
Detection count: 36
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: December 17, 2012
%SystemDrive%\Users\<username>\AppData\Roaming\DB41.exe File name: DB41.exe
Size: 46.59 KB (46592 bytes)
MD5: 6fd3767ce3f7b1feff120f9157afcde6
Detection count: 31
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Roaming
Group: Malware file
Last Updated: April 8, 2013
%ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\Startup\A-1503314171.exe File name: A-1503314171.exe
Size: 34.81 KB (34816 bytes)
MD5: 90a783bcb202174d96e0dbabba0262c7
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: February 6, 2013
%ALLUSERSPROFILE%\Local Settings\Temp\msdubmnax.pif File name: msdubmnax.pif
Size: 63.52 KB (63527 bytes)
MD5: 66b2d27683c41b280613e712a8e8da0f
Detection count: 7
Mime Type: unknown/pif
Path: %ALLUSERSPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: October 22, 2012
%APPDATA%\svchost.exe File name: svchost.exe
Size: 907.77 KB (907776 bytes)
MD5: e821fd5263c3cbfaefde266704dcd45e
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: April 10, 2013
C:\RECYCLER\S-1-5-21-0221221080-0036487367-414311101-0342\winmap.exe File name: winmap.exe
Size: 208.39 KB (208391 bytes)
MD5: 2bcf812ad0a67a869a22784cee68da96
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: C:\RECYCLER\S-1-5-21-0221221080-0036487367-414311101-0342
Group: Malware file
Last Updated: December 8, 2010
%WINDIR%\scvhosts.exe File name: scvhosts.exe
Size: 79.87 KB (79872 bytes)
MD5: 7801445b809b932a429f9387853caf81
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: May 8, 2020
%ALLUSERSPROFILE%\o0mf45nj.exe File name: o0mf45nj.exe
Size: 103.42 KB (103424 bytes)
MD5: e2668b12c194c2ed2b02171b02ec0070
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: August 16, 2012
%USERPROFILE%\My Documents\Downloads2\CMOInstaller.exe File name: CMOInstaller.exe
Size: 14.5 MB (14508841 bytes)
MD5: b23c48472de65d83b2b62619ae084157
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\My Documents\Downloads2
Group: Malware file
Last Updated: March 21, 2013
%USERPROFILE%\tofitugikloq.exe File name: tofitugikloq.exe
Size: 90.58 KB (90584 bytes)
MD5: e00f89b960bfde2c239c428bcb6bf73f
Detection count: 2
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: December 3, 2012

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\Software\ Backdoor.Ursap!rts
Loading...