Spy Trojan

How to remove “UDS:Trojan-Spy.Win32.Ursnif”?

Malware Removal

The UDS:Trojan-Spy.Win32.Ursnif is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-Spy.Win32.Ursnif virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine UDS:Trojan-Spy.Win32.Ursnif?


File Info:

crc32: 570B8802
md5: 048b54087505b524c9e4c5f4e1394afb
name: 048B54087505B524C9E4C5F4E1394AFB.mlw
sha1: 0c74e30542a1de22aa48413e493f6906668553df
sha256: 345ab39b904f12eeadb6b22abb93155b8fe4a0c33309227332c63c96447dcca6
sha512: 46a57add8f4f4fcaacf2041199e27e7bdfdae661b104ec840a25fbe1998bc21582c3c91d02ea77c1ce32160cf362b0ae4b431f4b7e5df1b4fa03430283ed6a64
ssdeep: 24576:HQfpzjXPgfw8CJV4X+IBIJ3cazaLwj1mCG9CpNiLi:IFDgkJV4OaIRj150CpNiLi
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

UDS:Trojan-Spy.Win32.Ursnif also known as:

DrWebTrojan.Gozi.803
ClamAVWin.Trojan.Johnnie-9854285-0
CAT-QuickHealTrojan.Gozi.S20892042
ALYacGen:Variant.Zusy.378666
ZillyaTrojan.Ursnif.Win32.12080
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Ursnif.7f768693
K7GWSpyware ( 005690661 )
K7AntiVirusSpyware ( 005690661 )
CyrenW32/Ursnif.DQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Ursnif.CG
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
CynetMalicious (score: 100)
KasperskyUDS:Trojan-Spy.Win32.Ursnif.gen
BitDefenderGen:Variant.Zusy.378666
NANO-AntivirusTrojan.Win32.Gozi.iumage
MicroWorld-eScanGen:Variant.Zusy.378666
TencentMalware.Win32.Gencirc.10ce5568
Ad-AwareGen:Variant.Zusy.378666
SophosMal/Generic-R + Troj/AGent-BGWX
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0DFK21
McAfee-GW-EditionTrojan-FTSS!048B54087505
FireEyeGen:Variant.Zusy.378666
EmsisoftTrojan-Spy.Ursnif (A)
JiangminTrojan.Agent.dgmy
AviraTR/Spy.Ursnif.ozghq
Antiy-AVLTrojan/Generic.ASMalwS.3292965
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Gozi.GP!MTB
GDataWin32.Trojan.PSE.1VI37ED
TACHYONTrojan/W32.Convagent.960000
AhnLab-V3Trojan/Win.Agent.R418408
McAfeeTrojan-FTSS!048B54087505
MAXmalware (ai score=80)
VBA32Trojan.Agent
MalwarebytesTrojan.Ursnif
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DFK21
RisingSpyware.Ursnif!1.D578 (CLASSIC)
YandexTrojanSpy.Ursnif!vDsZBfk4zy4
IkarusTrojan-Spy.Agent
FortinetW32/Kryptik.HKNN!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove UDS:Trojan-Spy.Win32.Ursnif?

UDS:Trojan-Spy.Win32.Ursnif removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment