Home Malware Programs Trojans TrojanSpy:Win64/Ursnif.C

TrojanSpy:Win64/Ursnif.C

Posted: July 30, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 199
First Seen: July 30, 2012
Last Seen: February 26, 2021
OS(es) Affected: Windows

TrojanSpy:Win64/Ursnif.C is a dangerous Trojan horse that could capture passwords and personal data on an infected PC. TrojanSpy:Win64/Ursnif.C may also be used by a remote hacker to gain access to the computer. TrojanSpy:Win64/Ursnif.C may be extremely difficult to manually remove due to it having rootkit capabilities and loading at startup of Windows. It may be beneficial to remove TrojanSpy:Win64/Ursnif.C using an antimalware program.

Aliases

Win32/Cryptor [AVG]W32/Zbot.CGZF!tr [Fortinet]Backdoor.Win32.Rbot [Ikarus]Worm/Win32.Kolab [AhnLab-V3]Worm/Win32.Kolab.gen [Antiy-AVL]WORM_KOLAB.YD [TrendMicro]TR/Crypt.ZPACK.Gen2 [AntiVir]BackDoor.IRC.Bot.166 [DrWeb]Heur.Suspicious [Comodo]Mal/EncPk-AEG [Sophos]Gen:Variant.Kazy.82169 [BitDefender]Net-Worm.Win32.Kolab.bitz [Kaspersky]Trojan.Gen.2 [Symantec]Exploit-DcomRpc!a [McAfee]I-Worm.Kolab.bitz [CAT-QuickHeal]
More aliases (61)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%PROGRAMFILES(x86)%\Vietkey2000\VKNT.EXE File name: VKNT.EXE
Size: 78.84 KB (78848 bytes)
MD5: 22f0b237a3da4957d17bb0e8dd5bce3e
Detection count: 89
File type: Executable File
Mime Type: unknown/EXE
Path: %PROGRAMFILES(x86)%\Vietkey2000\VKNT.EXE
Group: Malware file
Last Updated: November 9, 2022
%WINDIR%\yadrive32.exe File name: yadrive32.exe
Size: 49.15 KB (49152 bytes)
MD5: 2fc6e8d525a47bc308fed52f0f2a4d12
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%
Group: Malware file
Last Updated: August 1, 2012
%TEMP%\Locarint64.dll File name: Locarint64.dll
Size: 62.97 KB (62976 bytes)
MD5: cde6aca8ce75c23e287b04f634cb652a
Detection count: 13
File type: Dynamic link library
Mime Type: unknown/dll
Path: %TEMP%
Group: Malware file
Last Updated: July 30, 2012
%ALLUSERSPROFILE%\Application Data\hjaunofd.exe File name: hjaunofd.exe
Size: 57.34 KB (57344 bytes)
MD5: db8993e29b8261c650888b26a8170db0
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data
Group: Malware file
Last Updated: August 1, 2012
Loading...