Spy Trojan

TrojanSpy:Win32/Ursnif.HP removal guide

Malware Removal

The TrojanSpy:Win32/Ursnif.HP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Ursnif.HP virus can do?

  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanSpy:Win32/Ursnif.HP?


File Info:

crc32: 5E11F8F9
md5: a239bb4611bd5eed209d8ce8d0eb4487
name: A239BB4611BD5EED209D8CE8D0EB4487.mlw
sha1: 03eb828203a8d0e24b2596cf3fdcae05833aa099
sha256: f1c47c61f98011c2371e2e6d0b776b4ea2d066ffebaa2c0ad6a5f93e13ef9cc0
sha512: c5d3d4c675c77c7a373fbfb565b67a68fdf5611b435040b8632ea5175e2c0713319d8f53b12c1c92a3d5b240ca9049b36679b1f0ed7ad2bc8aa632af4b141bdc
ssdeep: 12288:8gPwJ57NgP46n03KZksJMM4wMLoBj19Mjv1m1g4l1aL:80cRijyKZkuM8M3v1ogsaL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanSpy:Win32/Ursnif.HP also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.68534
ALYacGen:Variant.Symmi.68534
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00515aa21 )
BitDefenderGen:Variant.Symmi.68534
K7GWTrojan ( 00515aa21 )
Cybereasonmalicious.611bd5
SymantecPacked.Generic.493
APEXMalicious
AvastWin32:Filecoder-BD [Trj]
KasperskyTrojan-Spy.Win32.Ursnif.xoy
AegisLabTrojan.Win32.Generic.4!c
RisingRansom.Cerber!8.3058 (CLOUD)
Ad-AwareGen:Variant.Symmi.68534
EmsisoftGen:Variant.Symmi.68534 (B)
F-SecureHeuristic.HEUR/AGEN.1105006
DrWebTrojan.MulDrop7.55153
ZillyaBackdoor.PePatch.Win32.110114
TrendMicroMal_Cerber-20
McAfee-GW-EditionBehavesLike.Win32.Ransomware.gc
FireEyeGeneric.mg.a239bb4611bd5eed
SophosML/PE-A + Mal/Elenoocka-E
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1105006
MAXmalware (ai score=98)
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftTrojanSpy:Win32/Ursnif.HP
ArcabitTrojan.Symmi.D10BB6
ZoneAlarmTrojan-Spy.Win32.Ursnif.xoy
GDataGen:Variant.Symmi.68534
CynetMalicious (score: 100)
Acronissuspicious
McAfeeRansomware-GDA!A239BB4611BD
VBA32BScope.Trojan.Zbot.01442
PandaTrj/GdSda.A
ESET-NOD32a variant of Generik.BBGVUAQ
TrendMicro-HouseCallMal_Cerber-20
IkarusTrojan-Ransom.Spora
eGambitUnsafe.AI_Score_80%
FortinetW32/Kryptik.GKVH!tr
BitDefenderThetaGen:NN.ZexaF.34590.zqW@aCPAtUai
AVGWin32:Filecoder-BD [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (D)
Qihoo-360Win32/Trojan.Spy.278

How to remove TrojanSpy:Win32/Ursnif.HP?

TrojanSpy:Win32/Ursnif.HP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment