Trojan

TrojanDropper:MSIL/Ursnif.GE!MTB removal instruction

Malware Removal

The TrojanDropper:MSIL/Ursnif.GE!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:MSIL/Ursnif.GE!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanDropper:MSIL/Ursnif.GE!MTB?


File Info:

crc32: EE11274D
md5: b94cf8dcb0b74f44bfebf091b8223fc7
name: upload_file
sha1: 2cf72f55b180f044601079278f963d9dfb2d12af
sha256: ba318072fe85e168c5fd55a30760ac306f75fa76c2d5ec40533b0505cda1c26d
sha512: 80a8d6e24b365e4d422c975a0bf40680fb6a766b16c29002ef3310d2bf60d974cf074aae0e34395c027d0545ab19e5b1aff65676e13ac971afde9de479669ffb
ssdeep: 24576:9zI+Iq3SgLDB2gIxpMuFuZ2DdnrHnSss3b3gBVKfSom6Zq/6WLm:VfDB21xpUAVHvs3b3gBVKfA
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: ready to spoof.exe
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename: ready to spoof.exe

TrojanDropper:MSIL/Ursnif.GE!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.681126
FireEyeGeneric.mg.b94cf8dcb0b74f44
CAT-QuickHealTrojan.Generic
ALYacGen:Variant.Razy.681126
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 00568bd81 )
BitDefenderGen:Variant.Razy.681126
K7GWTrojan ( 00568bd81 )
Cybereasonmalicious.5b180f
InvinceaMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34298.@n0@aytihle
CyrenW32/MSIL_Kryptik.AVX.gen!Eldorado
SymantecTrojan.Gen.MBT
TrendMicro-HouseCallTROJ_GEN.R002C0DJ220
AvastWin32:RATX-gen [Trj]
CynetMalicious (score: 85)
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanDropper:MSIL/Ursnif.7db4dd1b
NANO-AntivirusTrojan.Win32.Razy.hypqqw
ViRobotTrojan.Win32.Z.Razy.2086400.DP
AegisLabTrojan.Win32.Generic.4!c
APEXMalicious
Ad-AwareGen:Variant.Razy.681126
SophosMal/Generic-S
ComodoMalware@#2qounnbreoj17
F-SecureHeuristic.HEUR/AGEN.1134219
DrWebTrojan.MulDropNET.12
TrendMicroTROJ_GEN.R002C0DJ220
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGen:Variant.Razy.681126 (B)
SentinelOneDFI – Malicious PE
AviraHEUR/AGEN.1134219
MAXmalware (ai score=88)
MicrosoftTrojanDropper:MSIL/Ursnif.GE!MTB
ArcabitTrojan.Razy.DA64A6
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.681126
AhnLab-V3Malware/Win32.Generic.C866832
McAfeeArtemis!B94CF8DCB0B7
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.PCrypt.MSIL.Generic
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.EVL
YandexTrojan.Agent!XyVY91OvsbA
IkarusTrojan.MSIL.Krypt
eGambitUnsafe.AI_Score_77%
FortinetMSIL/GenKryptik.ELXR!tr
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.ae8

How to remove TrojanDropper:MSIL/Ursnif.GE!MTB?

TrojanDropper:MSIL/Ursnif.GE!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment