Home Malware Programs Trojans TrojanSpy:Win64/Ursnif.L

TrojanSpy:Win64/Ursnif.L

Posted: September 6, 2012

Threat Metric

Ranking: 16,791
Threat Level: 8/10
Infected PCs: 415
First Seen: September 6, 2012
Last Seen: September 15, 2023
OS(es) Affected: Windows

Aliases

Generic29.PNG [AVG]W32/Weelsof.EM!tr [Fortinet]Trojan.Win32.Weelsof [Ikarus]Mal/Weelsof-A [Sophos]TR/Weelsof.em [AntiVir]TrojWare.Win32.Agent.VAUGA [Comodo]Trojan.Generic.KDV.697751 [BitDefender]Trojan.Win32.Weelsof.em [Kaspersky]W32.Pilleuz!gen35 [Symantec]Artemis!F5B1313C9437 [McAfee]Dropper.Generic6.BHOD [AVG]W32/Zbot.ADN!tr [Fortinet]Trojan-Dropper.Win32.Necurs [Ikarus]Spyware/Win32.Zbot [AhnLab-V3]TR/Drop.Necurs.wk.1 [AntiVir]
More aliases (132)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\system32\NEUSBw32.dll File name: NEUSBw32.dll
Size: 157.18 KB (157184 bytes)
MD5: c06a18bb345bbfe8158ab88f1f1f4b04
Detection count: 211
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: September 10, 2012
%WINDIR%\System32\drivers\gpmm.sys File name: gpmm.sys
Size: 6.78 KB (6784 bytes)
MD5: 7ed96b2529369f06a15d0d519a23f4c9
Detection count: 52
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: September 10, 2012
%WINDIR%\System32\drivers\gpmn.sys File name: gpmn.sys
Size: 18.3 KB (18304 bytes)
MD5: 0ee3ceec262efea90b216c8379e2a4c8
Detection count: 52
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: September 10, 2012
%WINDIR%\Installer\{55948288-16F5-CF27-CB3E-EFA6AB1F7964}\syshost.exe File name: syshost.exe
Size: 359.93 KB (359936 bytes)
MD5: 90dab3b41bd3c980616be7b143f1bc5a
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\Installer\{55948288-16F5-CF27-CB3E-EFA6AB1F7964}
Group: Malware file
Last Updated: September 10, 2012
%SystemDrive%\documents and settings\invitado\configuraci?n local\temp\00016368.exe File name: 00016368.exe
Size: 258.04 KB (258048 bytes)
MD5: c7241f6ef4d5884ee61b1b8412f6cdd1
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\documents and settings\invitado\configuraci?n local\temp
Group: Malware file
Last Updated: September 10, 2012
%USERPROFILE%\zm7w6yqsxb.exe File name: zm7w6yqsxb.exe
Size: 20.96 KB (20960 bytes)
MD5: 7ceed788a1fbb0e5d356e49ccd2e9b0a
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%
Group: Malware file
Last Updated: September 10, 2012
%WINDIR%\system32\powedVol64.dll File name: powedVol64.dll
Size: 62.97 KB (62976 bytes)
MD5: 77bc865798da73f9f7dd9b4eef3cb40a
Detection count: 0
File type: Dynamic link library
Mime Type: unknown/dll
Path: %WINDIR%\system32
Group: Malware file
Last Updated: September 7, 2012
Loading...