Home Malware Programs Trojans TrojanSpy:Win64/Ursnif.Q

TrojanSpy:Win64/Ursnif.Q

Posted: January 28, 2013

Threat Metric

Threat Level: 8/10
Infected PCs: 23
First Seen: January 28, 2013
OS(es) Affected: Windows

Aliases

Application/BoontyGames [Panda]APPL [Ikarus]Backdoor/Win32.Agent.gen [Antiy-AVL]APPL/BoontyGames [AntiVir]W32/MalwareS.BHQT [F-Prot]Artemis!99C2B873BA91 [McAfee]Generic29.BDRG [AVG]MSIL/Injector.ANW [Fortinet]Win32.SuspectCrc [Ikarus]Trojan/Win32.Windef [AhnLab-V3]TR/Agent.396288.33 [AntiVir]Trojan.Packed.23343 [DrWeb]Trojan-FakeAV.Win32.Windef.zt [Kaspersky]Win32:Delf-SYH [Trj] [Avast]WS.Reputation.1 [Symantec]
More aliases (54)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%USERPROFILE%\Start Menu\Programs\Startup\ub0rtray.exe File name: ub0rtray.exe
Size: 495.89 KB (495890 bytes)
MD5: 687af7f369d86aa090356adf49e0c375
Detection count: 69
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Start Menu\Programs\Startup
Group: Malware file
Last Updated: January 29, 2013
%ALLUSERSPROFILE%\dialedit64.dll File name: dialedit64.dll
Size: 95.74 KB (95744 bytes)
MD5: bff7dbe1d6eb457c3f41613f2c61e382
Detection count: 41
File type: Dynamic link library
Mime Type: unknown/dll
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: January 28, 2013
%TEMP%\tmp1AD3.tmp.exe File name: tmp1AD3.tmp.exe
Size: 396.28 KB (396288 bytes)
MD5: 8eadf5c5187be5aec02ed49d2c10c6a2
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%
Group: Malware file
Last Updated: January 29, 2013
%COMMONPROGRAMFILES%\BOONTY Shared\Service\Boonty.exe File name: Boonty.exe
Size: 69.12 KB (69120 bytes)
MD5: 99c2b873ba915b51abc38f4fcc085a6b
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %COMMONPROGRAMFILES%\BOONTY Shared\Service
Group: Malware file
Last Updated: January 31, 2013
Loading...