Home Malware Programs Trojans TrojanSpy:Win64/Ursnif.AH

TrojanSpy:Win64/Ursnif.AH

Posted: April 2, 2013

Threat Metric

Threat Level: 8/10
Infected PCs: 19
First Seen: April 2, 2013
OS(es) Affected: Windows

Aliases

Generic Trojan [Panda]ILCrypt [AVG]W32/Jorik_IRCbot.THQ!tr [Fortinet]Trojan.Win32.Jorik [Ikarus]TROJ_GEN.RCBCAIR [TrendMicro]TR/Jorik.IRCbot.thq [AntiVir]Trojan.DownLoader6.54390 [DrWeb]UnclassifiedMalware [Comodo]Trojan.Win32.Jorik.IRCbot.thq [Kaspersky]Trojan [K7AntiVirus]Artemis!22D398A51F73 [McAfee]Trojan.Jorik.IRCbot.thq [CAT-QuickHeal]Trj/CI.A [Panda]Trojan.WinNT.Sirefef [Ikarus]Trojan.ADH [Symantec]
More aliases (44)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%TEMP%\ndaderpt64.dll File name: ndaderpt64.dll
Size: 64 KB (64000 bytes)
MD5: 3148053d49aace4e5d3ca3f3fc3fbb5c
Detection count: 39
File type: Dynamic link library
Mime Type: unknown/dll
Path: %TEMP%
Group: Malware file
Last Updated: April 2, 2013
%APPDATA%\B0AC.exe File name: B0AC.exe
Size: 46.59 KB (46592 bytes)
MD5: 5b1834cca1f6a75cf4865b27d77bf275
Detection count: 38
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: April 8, 2013
%USERPROFILE%\Belgelerim\IDM_Portable_6.11.8.2.0_Development_Test_1.paf.exe File name: IDM_Portable_6.11.8.2.0_Development_Test_1.paf.exe
Size: 5.62 MB (5629460 bytes)
MD5: 4f4fb9668760653805ce005b4ffc9698
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Belgelerim
Group: Malware file
Last Updated: April 8, 2013
%TEMP%\AlarmClock.exe File name: AlarmClock.exe
Size: 39.42 KB (39424 bytes)
MD5: 22d398a51f7359fa3759de941477efb1
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: April 8, 2013
Loading...