Trojan

About “Trojan:Win32/Ursnif.RP!MTB” infection

Malware Removal

The Trojan:Win32/Ursnif.RP!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ursnif.RP!MTB virus can do?

    Related domains:

    z.whorecord.xyz

    How to determine Trojan:Win32/Ursnif.RP!MTB?

    
    

    File Info:

    crc32: 5ED66BF6
    md5: 743e07c4c2ccb80ab58c041d6388e685
    name: 743E07C4C2CCB80AB58C041D6388E685.mlw
    sha1: c5af42bab5d14e63c1cc257989ad25337c8f137e
    sha256: 1b13ca64d43c95a3e8fea7a7c41fab2d1a0bcfe80575145d4342c3672428f307
    sha512: 23959febacae4a6403c691f69e2dcc2039d443197eecb274cad4a9ba0d93f79dc4aa27f992564e91242f77c7e43fa71dafb87d2b16311d0406ba3cd1bf2011ea
    ssdeep: 6144:7oHf/B9KBbOwf8Ngow+vlubIvhxwB5I6F:7oHf/BI9OgKXw+vwIZxw3F
    type: MS-DOS executable

    Version Info:

    0: [No Data]

    Trojan:Win32/Ursnif.RP!MTB also known as:

    LionicTrojan.Win32.Ursnif.4!c
    ClamAVWin.Malware.Ursnif-9884005-0
    ALYacGeneric.Ursnif.3.1.C1D79753
    CylanceUnsafe
    CrowdStrikewin/malicious_confidence_90% (W)
    AlibabaTrojanSpy:Win64/Ursnif.9cc04264
    K7GWSpyware ( 0057f4f21 )
    SymantecTrojan.Gen.MBT
    ESET-NOD32a variant of Win64/Spy.Ursnif.AP.gen
    APEXMalicious
    AvastWin64:Ursnif-E [Bank]
    CynetMalicious (score: 100)
    KasperskyTrojan.Win64.Agent.qwhxhy
    BitDefenderGeneric.Ursnif.3.1.C1D79753
    MicroWorld-eScanGeneric.Ursnif.3.1.C1D79753
    Ad-AwareGeneric.Ursnif.3.1.C1D79753
    SophosGeneric ML PUA (PUA)
    TrendMicroTROJ_FRS.0NA103IK21
    McAfee-GW-EditionBehavesLike.Win64.Generic.dh
    FireEyeGeneric.mg.743e07c4c2ccb80a
    EmsisoftGeneric.Ursnif.3.1.C1D79753 (B)
    WebrootW32.Malware.Gen
    AviraHEUR/AGEN.1108168
    eGambitUnsafe.AI_Score_86%
    KingsoftWin32.Troj.Undef.(kcloud)
    MicrosoftTrojan:Win32/Ursnif.RP!MTB
    ArcabitGeneric.Ursnif.3.1.C1D79753
    ZoneAlarmTrojan.Win64.Agent.qwhxhy
    GDataGeneric.Ursnif.3.1.C1D79753
    AhnLab-V3Malware/Win.Ursnif.C4567690
    McAfeeRDN/Generic PWS.y
    MAXmalware (ai score=82)
    MalwarebytesMalware.AI.2530209770
    TrendMicro-HouseCallTROJ_FRS.0NA103IK21
    IkarusTrojan.Win64.Spy
    MaxSecureTrojan.Malware.300983.susgen
    FortinetW64/Agent.BCNL!tr
    AVGWin64:Ursnif-E [Bank]

    How to remove Trojan:Win32/Ursnif.RP!MTB?

    Trojan:Win32/Ursnif.RP!MTB removal tool
    • Download and install GridinSoft Anti-Malware.
    • Open GridinSoft Anti-Malware and perform a “Standard scan“.
    • Move to quarantine” all items.
    • Open “Tools” tab – Press “Reset Browser Settings“.
    • Select proper browser and options – Click “Reset”.
    • Restart your computer.

    About the author

    Paul Valéry

    I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

    Leave a Comment