Home Malware Programs Trojans TrojanSpy:Win64/Ursnif.AF

TrojanSpy:Win64/Ursnif.AF

Posted: April 2, 2013

Threat Metric

Ranking: 12,324
Threat Level: 8/10
Infected PCs: 9,914
First Seen: April 2, 2013
Last Seen: September 2, 2023
OS(es) Affected: Windows

TrojanSpy:Win64/Ursnif.AF is a dangerous Trojan horse that may download files that cause an infected system to open up access for a remote hacker. This access obtained through TrojanSpy:Win64/Ursnif.AF may allow theft of data stored on the infected PC, which could easily lead to identity theft. TrojanSpy:Win64/Ursnif.AF usually loads and runs in the background where it may run undetected for long periods of time. Eliminating TrojanSpy:Win64/Ursnif.AF with antispyware software will ensure remote attackers are not able to infiltrate your computer.

Aliases

not-a-virus:Monitor.Win32.KeyLogger.bdy [Kaspersky]Adware/BaiduBar [Panda]Generic4.NLP [AVG]not-a-virus:AdWare.Win32.Agent [Ikarus]Win-AppCare/Xema.294912.R [AhnLab-V3]Adware:Win32/DoubleD [Microsoft]AdWare/Win32.Agent.gen [Antiy-AVL]ADSPY/Agent.pkv [AntiVir]Application.Generic.237274 [BitDefender]not-a-virus:AdWare.Win32.Agent.pkv [Kaspersky]Win32:Adware-gen [Avast]W32/MalwareS.IYS [F-Prot]Adware [K7AntiVirus]AdWare.Agent.pkv (Not a Virus) [CAT-QuickHeal]MSIL.DTP [AVG]
More aliases (524)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\system32\DisrIbs.dll File name: DisrIbs.dll
Size: 2.13 MB (2138112 bytes)
MD5: fa47f6e849daa90cfdd337f667c2f600
Detection count: 95
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: April 10, 2013
%SystemDrive%\Temporary\iehighutil.exe File name: iehighutil.exe
Size: 526.24 KB (526249 bytes)
MD5: 75bd6e532370c06c567718d68e551647
Detection count: 66
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Temporary
Group: Malware file
Last Updated: April 8, 2013
%LOCALAPPDATA%\KoreanKeyword\WinKeyword.exe File name: WinKeyword.exe
Size: 221.66 KB (221664 bytes)
MD5: 599e792db3be64534286e5637f9adb85
Detection count: 63
File type: Executable File
Mime Type: unknown/exe
Path: %LOCALAPPDATA%\KoreanKeyword
Group: Malware file
Last Updated: April 8, 2013
C:\Users\<username>\Desktop\Switchbotv3_0_0_5\core\switchbot.dll File name: switchbot.dll
Size: 625.66 KB (625664 bytes)
MD5: 2b6c2849652d47844ca395fb6bbc0ffd
Detection count: 37
File type: Dynamic link library
Mime Type: unknown/dll
Path: C:\Users\<username>\Desktop\Switchbotv3_0_0_5\core\switchbot.dll
Group: Malware file
Last Updated: September 27, 2022
C:\Users\<username>\AppData\Local\Temp\RarSFX0\winfile.exe File name: winfile.exe
Size: 1.15 MB (1157863 bytes)
MD5: 48ed06fe2d2ed564de0edc6f8d0b123f
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\AppData\Local\Temp\RarSFX0\winfile.exe
Group: Malware file
Last Updated: January 27, 2023
D:\Program Files\System Search Dispatcher\1.4.0.970\ssd.dll File name: ssd.dll
Size: 294.91 KB (294912 bytes)
MD5: 141b43033b11005415ad33411fcf5d59
Detection count: 23
File type: Dynamic link library
Mime Type: unknown/dll
Path: D:\Program Files\System Search Dispatcher\1.4.0.970
Group: Malware file
Last Updated: May 8, 2013
%APPDATA%\top1.exe File name: top1.exe
Size: 30.72 KB (30720 bytes)
MD5: bb6815957e8359ad22e962525443f908
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: April 8, 2013
C:\Program Files\Java\svchost.exe File name: svchost.exe
Size: 510.99 KB (510990 bytes)
MD5: 61d0fdbddb8763b79054001f591d071a
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: C:\Program Files\Java\svchost.exe
Group: Malware file
Last Updated: June 22, 2021
%USERPROFILE%\S-100-4902-8593-5693\winmgr.exe File name: winmgr.exe
Size: 315.39 KB (315392 bytes)
MD5: aeba6022c57066e0dd54620e24de1fd5
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\S-100-4902-8593-5693
Group: Malware file
Last Updated: April 8, 2013
%WINDIR%\system32\ucmbgmodqtk.exe File name: ucmbgmodqtk.exe
Size: 110.59 KB (110592 bytes)
MD5: 8fdb9757433e2817d4d6c373e140d9da
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: April 8, 2013
%USERPROFILE%\Mes documents\Downloads\SmitfraudFix.exe File name: SmitfraudFix.exe
Size: 1.88 MB (1883662 bytes)
MD5: 0d5fc73f4e0e92c1d6062759c2f9be7c
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Mes documents\Downloads
Group: Malware file
Last Updated: April 10, 2013
%USERPROFILE%\Documents\Services\ff.exe File name: ff.exe
Size: 969.07 KB (969072 bytes)
MD5: 38019dbdbdbfba812fe15fb1c51e7497
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Documents\Services
Group: Malware file
Last Updated: April 8, 2013
%ALLUSERSPROFILE%\Microsoft\Windows\Templates\5ca13f6c9495c07d.exe File name: 5ca13f6c9495c07d.exe
Size: 907.74 KB (907740 bytes)
MD5: 7cdaa4ac0a8d0a56085968001f3df059
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Microsoft\Windows\Templates
Group: Malware file
Last Updated: April 10, 2013
%ALLUSERSPROFILE%\wtlsciilrckdg.exe File name: wtlsciilrckdg.exe
Size: 304.12 KB (304128 bytes)
MD5: 00840bc9c8249e3ecc21ba268e6e2d5a
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: April 8, 2013
%USERPROFILE%\impostazioni locali\dati applicazioni\lollipop\lollipop_03161418.exe File name: lollipop_03161418.exe
Size: 892.41 KB (892416 bytes)
MD5: fee97f9465a762a2cd3d24aab40f36e0
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\impostazioni locali\dati applicazioni\lollipop
Group: Malware file
Last Updated: April 10, 2013
%SystemDrive%\Users\<username>\AppData\Roaming\skype.dat File name: skype.dat
Size: 131.07 KB (131072 bytes)
MD5: 5ab611b2a806d25c08e9f6fd287b618f
Detection count: 5
File type: Data file
Mime Type: unknown/dat
Path: %SystemDrive%\Users\<username>\AppData\Roaming
Group: Malware file
Last Updated: April 8, 2013

More files
Loading...