Home Malware Programs Trojans TrojanSpy:Win64/Ursnif.A

TrojanSpy:Win64/Ursnif.A

Posted: December 12, 2011

Threat Metric

Ranking: 16,744
Threat Level: 8/10
Infected PCs: 21,306
First Seen: December 12, 2011
Last Seen: September 7, 2023
OS(es) Affected: Windows

TrojanSpy:Win64/Ursnif.A is a Trojan with spyware capabilities that enables an attacker to get backdoor access and control of the affected computer. Once installed on the infected computer system, TrojanSpy:Win64/Ursnif.A steals personal information and transmits it to the remote attacker. TrojanSpy:Win64/Ursnif.A may be installed on the compromised PC via drive-by download attacks, if the computer user visits a hijacked or malicious website. TrojanSpy:Win64/Ursnif.A may also be installed by other PC threats. TrojanSpy:Win64/Ursnif.A connects to a remote server to receive instructions from a remote attacker. TrojanSpy:Win64/Ursnif.A grabs FTP transfer data (GET/PUT commands) and HTTP outbound traffic (POST data), gets your browser cookies and digital certificates, captures screenshots, clears browser cookies, and performs numerous other malicious actions. TrojanSpy:Win64/Ursnif.A inserts itself into the legitimate web browser processes.

Aliases

W32/Ursnif.PEM!tr [Fortinet]TrojanSpy:Win32/Ursnif.gen!K [Microsoft]Artemis!E67E824460B5 [McAfee-GW-Edition]TR/Spy.Ursnif.K.168 [AntiVir]Mal/Generic-S [Sophos]Trojan.GenericKDV.1065624 [BitDefender]Trojan-Spy.Win32.Ursnif.pem [Kaspersky]RDN/Generic PWS.y!ta [McAfee]Win32:Crypt-NWY [Trj] [Avast]W32/Ursnif.B!tr [Fortinet]PWS-FADX!594091811002 [McAfee]W32/Papras.FGI!tr.bdr [Fortinet]TR/Crypt.XPACK.Gen3 [AntiVir]Trojan-Spy.Win32.Ursnif.b [Kaspersky]PWS-FADX!0603BF770C11 [McAfee]
More aliases (1141)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SystemDrive%\RECYCLER\S-1-5-21-842925246-1450960922-1801674531-1003\$f0f98dd8d3abadbdf1b04d8800d0764b\n. File name: n.
Size: 59.39 KB (59392 bytes)
MD5: 694cfd39050fafb121bc7250c8b7ad45
Detection count: 98
Path: %SystemDrive%\RECYCLER\S-1-5-21-842925246-1450960922-1801674531-1003\$f0f98dd8d3abadbdf1b04d8800d0764b
Group: Malware file
Last Updated: January 14, 2013
%USERPROFILE%\pkms.exe File name: pkms.exe
Size: 286.2 KB (286208 bytes)
MD5: ed07df1a68f1b36055dbeebfb77383fb
Detection count: 92
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: January 8, 2013
%ALLUSERSPROFILE%\lxbfmote64.dll File name: lxbfmote64.dll
Size: 93.18 KB (93184 bytes)
MD5: 175ce484e7d657938a58c61753fa9267
Detection count: 85
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: April 29, 2013
%LOCALAPPDATA%\WideSearch\wsearch.exe File name: wsearch.exe
Size: 416.25 KB (416256 bytes)
MD5: 013f153b253b33a88317aa77ead9e52b
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\WideSearch
Group: Malware file
Last Updated: January 8, 2013
%WINDIR%\makepugc64.dll File name: makepugc64.dll
Size: 67.07 KB (67072 bytes)
MD5: 12732b35e36e5877be63fcb8468241d6
Detection count: 64
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%
Group: Malware file
Last Updated: April 16, 2013
%LOCALAPPDATA%\WideSearch\wsearch.exe File name: wsearch.exe
Size: 416.25 KB (416256 bytes)
MD5: 33bc73c20f9c0f786bc7ff32a97ba700
Detection count: 59
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\WideSearch
Group: Malware file
Last Updated: January 8, 2013
%WINDIR%\system32\ReAgvate64.dll File name: ReAgvate64.dll
Size: 72.19 KB (72192 bytes)
MD5: f30a1f02f85145d5efeab5a45e6728e0
Detection count: 50
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: April 8, 2013
%APPDATA%\Nbt\Nbt.exe File name: Nbt.exe
Size: 776.19 KB (776192 bytes)
MD5: 74d81e494f2bca0785f1327eca65c851
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Nbt
Group: Malware file
Last Updated: January 8, 2013
%USERPROFILE%\My Documents\Downloads\Compressed\RevoHack Premium 24September2012\RevoHack.dll File name: RevoHack.dll
Size: 728.06 KB (728064 bytes)
MD5: beee1db6dd40d62ec2ba98d47d98f72b
Detection count: 33
File type: Dynamic link library
Mime Type: unknown/dll
Path: %USERPROFILE%\My Documents\Downloads\Compressed\RevoHack Premium 24September2012
Group: Malware file
Last Updated: January 8, 2013
%USERPROFILE%\My Documents\Downloads\Compressed\TrialWinXP\RevoHack.dll File name: RevoHack.dll
Size: 842.75 KB (842752 bytes)
MD5: 063148b684125bb95b9e5e49d5baff83
Detection count: 32
File type: Dynamic link library
Mime Type: unknown/dll
Path: %USERPROFILE%\My Documents\Downloads\Compressed\TrialWinXP
Group: Malware file
Last Updated: January 8, 2013
%USERPROFILE%\My Documents\Downloads\Compressed\PremiumhackDragonNest\RevoHack.dll File name: RevoHack.dll
Size: 727.55 KB (727552 bytes)
MD5: 52c1309cbb99532af537af0ae62aaa86
Detection count: 31
File type: Dynamic link library
Mime Type: unknown/dll
Path: %USERPROFILE%\My Documents\Downloads\Compressed\PremiumhackDragonNest
Group: Malware file
Last Updated: January 8, 2013
%USERPROFILE%\Local Settings\Application Data\Coupon Companion\Adobe\zdbvdzw.dll File name: zdbvdzw.dll
Size: 269.31 KB (269312 bytes)
MD5: 1d46d5e87cbc5b6d1c8e5a5e7024f658
Detection count: 30
File type: Dynamic link library
Mime Type: unknown/dll
Path: %USERPROFILE%\Local Settings\Application Data\Coupon Companion\Adobe
Group: Malware file
Last Updated: January 8, 2013
C:\Users\<username>\Downloads\testdisk-7.2-WIP\recup_dir.23\f91158992.exe File name: f91158992.exe
Size: 425.98 KB (425984 bytes)
MD5: 9fa47a30818710e86b0880d20b07355e
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Downloads\testdisk-7.2-WIP\recup_dir.23\f91158992.exe
Group: Malware file
Last Updated: November 28, 2022
%LOCALAPPDATA%\Microsoft\HuluDesktop\slwljjvb.dll File name: slwljjvb.dll
Size: 291.84 KB (291840 bytes)
MD5: 670cfaeaa9fe0abfe9cc91f4d1cbf5d9
Detection count: 23
File type: Dynamic link library
Mime Type: unknown/dll
Path: %LOCALAPPDATA%\Microsoft\HuluDesktop
Group: Malware file
Last Updated: January 14, 2013
%APPDATA%\Nbt\Nbt.exe File name: Nbt.exe
Size: 720.38 KB (720384 bytes)
MD5: 60627b628b732ddabee0aaa4b0d4ba8e
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Nbt
Group: Malware file
Last Updated: January 8, 2013
%APPDATA%\xclw3zeup1cqkruh3uvw1populzbp3mu\svcnost.exe File name: svcnost.exe
Size: 250.36 KB (250368 bytes)
MD5: a6f5a07088ea4f0c7f40fdc1361fc045
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\xclw3zeup1cqkruh3uvw1populzbp3mu
Group: Malware file
Last Updated: January 8, 2013
%WINDIR%\system32\cmdkmsdt64.dll File name: cmdkmsdt64.dll
Size: 72.7 KB (72704 bytes)
MD5: cc63230b29a0637fff28102b428def81
Detection count: 10
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: March 29, 2013
%SystemDrive%\system32\smss.exe File name: smss.exe
Size: 218.11 KB (218112 bytes)
MD5: 522bb21a447c46ed17765ef80f56f2d0
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\system32
Group: Malware file
Last Updated: January 8, 2013
%TEMP%\autoexec64.dll File name: autoexec64.dll
Size: 68.6 KB (68608 bytes)
MD5: ad33f4584e1d6a2be98cea08de2b8f63
Detection count: 5
File type: Dynamic link library
Mime Type: unknown/dll
Path: %TEMP%
Group: Malware file
Last Updated: March 1, 2013
%WINDIR%\system32\runadctr64.dll File name: runadctr64.dll
Size: 69.63 KB (69632 bytes)
MD5: 6ca30479837f7bbf4ddbc2af728a77ef
Detection count: 3
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: April 16, 2013

More files

Related Posts

Loading...