Home Malware Programs Trojans TrojanSpy:Win64/Ursnif.AG

TrojanSpy:Win64/Ursnif.AG

Posted: October 23, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 16
First Seen: October 23, 2012
OS(es) Affected: Windows

Aliases

Generic Trojan [Panda]PSW.Generic9.CMGR [AVG]W32/Generic.PO!tr [Fortinet]MSIL [Ikarus]Trojan/Win32.Jorik [AhnLab-V3]Trojan/win32.agent.gen [Antiy-AVL]TR/Dropper.Gen [AntiVir]Trojan.DownLoader6.20460 [DrWeb]Gen:Variant.Kazy.54395 [BitDefender]HEUR:Trojan.Win32.Generic [Kaspersky]MSIL:Ainslot-F [Trj] [Avast]Trojan.Gen [Symantec]Win32/Agent.TUH [NOD32]PWS-Zbot.gen.po [McAfee]Suspicious file [Panda]
More aliases (53)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\cleaperf64.dll File name: cleaperf64.dll
Size: 61.95 KB (61952 bytes)
MD5: 98c62700dd19a213d5db35f250c0a740
Detection count: 7
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%
Group: Malware file
Last Updated: October 23, 2012
%USERPROFILE%\ocsca.exe File name: ocsca.exe
Size: 180.22 KB (180224 bytes)
MD5: 62c06d520f604f60457c470fbcdcbc52
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: October 25, 2012
%PROGRAMFILES%\Messenger\OjkiydPassword\OjkiydPass1.exe File name: OjkiydPass1.exe
Size: 24.57 KB (24576 bytes)
MD5: 9511d849b36fca95251a7d1fd84f454d
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES%\Messenger\OjkiydPassword
Group: Malware file
Last Updated: October 24, 2012
Loading...