Trojan

How to remove “Trojan:Win32/Ursnif.SA!rfn”?

Malware Removal

The Trojan:Win32/Ursnif.SA!rfn is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Ursnif.SA!rfn virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan:Win32/Ursnif.SA!rfn?


File Info:

name: 8BFB8346C18CFD877212.mlw
path: /opt/CAPEv2/storage/binaries/cb4f92bf9fef3708e7aeba5d8994a0502952d06374c8a83ff2c1ee0b7e603d35
crc32: B3FB4025
md5: 8bfb8346c18cfd877212d689dac795b3
sha1: 4aecc1136edfe1a8351bc944898d86ade453532b
sha256: cb4f92bf9fef3708e7aeba5d8994a0502952d06374c8a83ff2c1ee0b7e603d35
sha512: 359b6f9ea227a716d5f8ebe95617e20031a5249fab46f96a8056f8f23c86e4770fc45e0e707e50cd8d8937d988b19f2ce2a19f4bc37c1dac0bc00fb08a4d461f
ssdeep: 768:cw9q2ruRo1IuipwvzX3g5U6qUReG+m2S8MsmzSnumGAyVDPtt7e2AH:cJ2rmokwv7w506bCmWuvVjt02
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14A63E167CD614A7BFB6260350268796E7DDCC319087BCC41C5BB9459AA3682EF4FB302
sha3_384: af342382668d03f25c4f1205e1968f5b106cb7eea1e5358d9535099f290d4380538208b2f3f1eacaf3c2ac358b679965
ep_bytes: 5633f656680000400056ff1520304000
timestamp: 2020-07-07 12:43:03

Version Info:

0: [No Data]

Trojan:Win32/Ursnif.SA!rfn also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ursnif.7!c
Elasticmalicious (high confidence)
DrWebTrojan.Gozi.710
MicroWorld-eScanGen:Variant.Fugrafa.80440
FireEyeGeneric.mg.8bfb8346c18cfd87
SkyhighBehavesLike.Win32.Generic.km
ALYacSpyware.Ursnif
MalwarebytesMalware.AI.1802224657
ZillyaTrojan.Ursnif.Win32.11709
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 005526431 )
AlibabaTrojanBanker:Win32/Ursnif.07553530
K7GWSpyware ( 005526431 )
Cybereasonmalicious.6c18cf
ArcabitTrojan.Fugrafa.D13A38
BitDefenderThetaAI:Packer.429CD8031E
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Spy.Ursnif.CT
APEXMalicious
TrendMicro-HouseCallTrojanSpy.Win32.URSNIF.TIABOEGZ
ClamAVWin.Malware.GoziISFB-9940853-2
KasperskyTrojan-Banker.Win32.Gozi.lnf
BitDefenderGen:Variant.Fugrafa.80440
NANO-AntivirusTrojan.Win32.Gozi.hpfrrc
AvastWin32:Ursnif-BW [Trj]
TencentMalware.Win32.Gencirc.13af7d49
EmsisoftGen:Variant.Fugrafa.80440 (B)
GoogleDetected
F-SecureTrojan.TR/AD.UrsnifDropper.gjdfp
VIPREGen:Variant.Fugrafa.80440
TrendMicroTrojanSpy.Win32.URSNIF.TIABOEGZ
Trapminemalicious.high.ml.score
SophosMal/Generic-S
IkarusTrojan-Spy.Agent
JiangminTrojan.Banker.Gozi.bbq
WebrootW32.Trojan.Gen
VaristW32/ABTrojan.IJFY-0947
AviraTR/AD.UrsnifDropper.gjdfp
Antiy-AVLTrojan[Spy]/Win32.Ursnif
Kingsoftmalware.kb.a.1000
XcitiumMalware@#13ispn17cp1kh
MicrosoftTrojan:Win32/Ursnif.SA!rfn
ZoneAlarmTrojan-Banker.Win32.Gozi.lnf
GDataGen:Variant.Fugrafa.80440
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Ursnif.C4170293
McAfeeGenericRXJC-QV!8BFB8346C18C
MAXmalware (ai score=83)
VBA32BScope.TrojanPSW.Papras
Cylanceunsafe
PandaTrj/CI.A
RisingSpyware.Ursnif!8.1DEF (TFE:1:hrNyabgzazH)
SentinelOneStatic AI – Malicious PE
MaxSecureVirus.Patched.OF
FortinetW32/Ursnif.CT!tr
AVGWin32:Ursnif-BW [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)
alibabacloudTrojan

How to remove Trojan:Win32/Ursnif.SA!rfn?

Trojan:Win32/Ursnif.SA!rfn removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment