Home Malware Programs Trojans Trojan.Spy.Ursnif.GL

Trojan.Spy.Ursnif.GL

Posted: July 20, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 1,110
First Seen: July 20, 2012
OS(es) Affected: Windows

Aliases

Logger.ADWS [AVG]Application.EliteKeyLogger [Ikarus]a variant of Win32/KeyLogger.EliteKeylogger.NAA [NOD32]BHO.WIH [AVG]W32/Browin!tr [Fortinet]Trojan.Win32.BHO [Ikarus]Troj/Browin-Gen [Sophos]Generic.dx!b2zf [McAfee]Trj/Thed.B [Panda]KGB Keylogger [Sophos]Trojan.KGBKeylog [ClamAV]a variant of Win32/KeyLogger.Refog.B [NOD32]Keylog-Refog [McAfee]Generic27.HHU [AVG]not-a-virus:AdWare.Win32.Gaba [Ikarus]
More aliases (67)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES%\OApps\bho_project.dll File name: bho_project.dll
Size: 92.16 KB (92160 bytes)
MD5: a6f35bf0d15e4e7403edb0171c44021c
Detection count: 1,038
File type: Dynamic link library
Mime Type: unknown/dll
Path: %PROGRAMFILES%\OApps
Group: Malware file
Last Updated: July 23, 2012
%WINDIR%\system32\MPK\mpk.exe File name: mpk.exe
Size: 1.37 MB (1372504 bytes)
MD5: aca33717b2861eb6ad5cb9896f8774d7
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32\MPK
Group: Malware file
Last Updated: July 23, 2012
%APPDATA%\Microsoft\Windows\AdvService.exe File name: AdvService.exe
Size: 421.88 KB (421888 bytes)
MD5: f0962c5aaaf7891744c357a22fd75cea
Detection count: 28
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Windows
Group: Malware file
Last Updated: July 23, 2012
%WINDIR%\System32\drivers\dmbootnt.sys File name: dmbootnt.sys
Size: 24.06 KB (24064 bytes)
MD5: 53d74720700a0389608fdee39c9b8866
Detection count: 7
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: July 30, 2012
%ALLUSERSPROFILE%\Application Data\17de54\BA17d_8034.exe File name: BA17d_8034.exe
Size: 3.65 MB (3650048 bytes)
MD5: 577bed697149a1710704068825cc4da2
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data\17de54
Group: Malware file
Last Updated: July 23, 2012
Loading...