Home Malware Programs Trojans TrojanSpy:Win64/Ursnif.AE

TrojanSpy:Win64/Ursnif.AE

Posted: February 22, 2013

Threat Metric

Threat Level: 8/10
Infected PCs: 9
First Seen: February 22, 2013
OS(es) Affected: Windows

Aliases

Dropper.Generic6.AHZQ [AVG]Trojan.Win32.VB [Ikarus]Win32:VB-ADQI [GData]Trojan/Win32.Gimemo [AhnLab-V3]Heuristic.LooksLike.Win32.Suspicious.B [McAfee-GW-Edition]Trojan.PWS.Panda.2401 [DrWeb]HEUR:Trojan.Win32.Generic [Kaspersky]Win32:VB-ADQI [Trj] [Avast]Trojan.Gen [Symantec]Artemis!1D21F85FBE22 [McAfee]Dropper.Generic6.BEFE [AVG]W32/VB.BTFE!tr [Fortinet]Trojan.Win32.Jorik [Ikarus]Heuristic.BehavesLike.Win32.Suspicious-DTR.G [McAfee-GW-Edition]TR/Kazy.87367.1 [AntiVir]
More aliases (61)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\99BF.exe File name: 99BF.exe
Size: 46.59 KB (46592 bytes)
MD5: d425d8cc3a294f9f944297ddcd770b9a
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: February 25, 2013
%WINDIR%\system32\mshtdctr64.dll File name: mshtdctr64.dll
Size: 58.88 KB (58880 bytes)
MD5: b3e896e01b328da1cd4ebe3c7907f57d
Detection count: 12
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: February 22, 2013
%LOCALAPPDATA%\ANAMARIA-PCth.exe File name: ANAMARIA-PCth.exe
Size: 299 KB (299008 bytes)
MD5: 1d21f85fbe222daf803af49986dc5dbc
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%
Group: Malware file
Last Updated: February 25, 2013
Loading...