TrojanSpy:Win64/Ursnif.AF
Posted: April 2, 2013
Threat Metric
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
Ranking: | 12,324 |
---|---|
Threat Level: | 8/10 |
Infected PCs: | 9,914 |
First Seen: | April 2, 2013 |
---|---|
Last Seen: | September 2, 2023 |
OS(es) Affected: | Windows |
TrojanSpy:Win64/Ursnif.AF is a dangerous Trojan horse that may download files that cause an infected system to open up access for a remote hacker. This access obtained through TrojanSpy:Win64/Ursnif.AF may allow theft of data stored on the infected PC, which could easily lead to identity theft. TrojanSpy:Win64/Ursnif.AF usually loads and runs in the background where it may run undetected for long periods of time. Eliminating TrojanSpy:Win64/Ursnif.AF with antispyware software will ensure remote attackers are not able to infiltrate your computer.
Aliases
More aliases (524)
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:%WINDIR%\system32\DisrIbs.dll
File name: DisrIbs.dllSize: 2.13 MB (2138112 bytes)
MD5: fa47f6e849daa90cfdd337f667c2f600
Detection count: 95
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: April 10, 2013
%SystemDrive%\Temporary\iehighutil.exe
File name: iehighutil.exeSize: 526.24 KB (526249 bytes)
MD5: 75bd6e532370c06c567718d68e551647
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Temporary
Group: Malware file
Last Updated: April 8, 2013
%LOCALAPPDATA%\KoreanKeyword\WinKeyword.exe
File name: WinKeyword.exeSize: 221.66 KB (221664 bytes)
MD5: 599e792db3be64534286e5637f9adb85
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\KoreanKeyword
Group: Malware file
Last Updated: April 8, 2013
C:\Users\<username>\Desktop\Switchbotv3_0_0_5\core\switchbot.dll
File name: switchbot.dllSize: 625.66 KB (625664 bytes)
MD5: 2b6c2849652d47844ca395fb6bbc0ffd
Detection count: 37
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Users\<username>\Desktop\Switchbotv3_0_0_5\core\switchbot.dll
Group: Malware file
Last Updated: September 27, 2022
C:\Users\<username>\AppData\Local\Temp\RarSFX0\winfile.exe
File name: winfile.exeSize: 1.15 MB (1157863 bytes)
MD5: 48ed06fe2d2ed564de0edc6f8d0b123f
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\RarSFX0\winfile.exe
Group: Malware file
Last Updated: January 27, 2023
D:\Program Files\System Search Dispatcher\1.4.0.970\ssd.dll
File name: ssd.dllSize: 294.91 KB (294912 bytes)
MD5: 141b43033b11005415ad33411fcf5d59
Detection count: 23
File type: Dynamic link library
Mime Type: unknown/dll
Path: D:\Program Files\System Search Dispatcher\1.4.0.970
Group: Malware file
Last Updated: May 8, 2013
%APPDATA%\top1.exe
File name: top1.exeSize: 30.72 KB (30720 bytes)
MD5: bb6815957e8359ad22e962525443f908
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: April 8, 2013
C:\Program Files\Java\svchost.exe
File name: svchost.exeSize: 510.99 KB (510990 bytes)
MD5: 61d0fdbddb8763b79054001f591d071a
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\Java\svchost.exe
Group: Malware file
Last Updated: June 22, 2021
%USERPROFILE%\S-100-4902-8593-5693\winmgr.exe
File name: winmgr.exeSize: 315.39 KB (315392 bytes)
MD5: aeba6022c57066e0dd54620e24de1fd5
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\S-100-4902-8593-5693
Group: Malware file
Last Updated: April 8, 2013
%WINDIR%\system32\ucmbgmodqtk.exe
File name: ucmbgmodqtk.exeSize: 110.59 KB (110592 bytes)
MD5: 8fdb9757433e2817d4d6c373e140d9da
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: April 8, 2013
%USERPROFILE%\Mes documents\Downloads\SmitfraudFix.exe
File name: SmitfraudFix.exeSize: 1.88 MB (1883662 bytes)
MD5: 0d5fc73f4e0e92c1d6062759c2f9be7c
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Mes documents\Downloads
Group: Malware file
Last Updated: April 10, 2013
%USERPROFILE%\Documents\Services\ff.exe
File name: ff.exeSize: 969.07 KB (969072 bytes)
MD5: 38019dbdbdbfba812fe15fb1c51e7497
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Documents\Services
Group: Malware file
Last Updated: April 8, 2013
%ALLUSERSPROFILE%\Microsoft\Windows\Templates\5ca13f6c9495c07d.exe
File name: 5ca13f6c9495c07d.exeSize: 907.74 KB (907740 bytes)
MD5: 7cdaa4ac0a8d0a56085968001f3df059
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Windows\Templates
Group: Malware file
Last Updated: April 10, 2013
%ALLUSERSPROFILE%\wtlsciilrckdg.exe
File name: wtlsciilrckdg.exeSize: 304.12 KB (304128 bytes)
MD5: 00840bc9c8249e3ecc21ba268e6e2d5a
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: April 8, 2013
%USERPROFILE%\impostazioni locali\dati applicazioni\lollipop\lollipop_03161418.exe
File name: lollipop_03161418.exeSize: 892.41 KB (892416 bytes)
MD5: fee97f9465a762a2cd3d24aab40f36e0
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\impostazioni locali\dati applicazioni\lollipop
Group: Malware file
Last Updated: April 10, 2013
%SystemDrive%\Users\<username>\AppData\Roaming\skype.dat
File name: skype.datSize: 131.07 KB (131072 bytes)
MD5: 5ab611b2a806d25c08e9f6fd287b618f
Detection count: 5
File type: Data file
Mime Type: unknown/dat
Path: %SystemDrive%\Users\<username>\AppData\Roaming
Group: Malware file
Last Updated: April 8, 2013
More files
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.