Spy

Should I remove “Win32/Spy.Ursnif.AJ”?

Malware Removal

The Win32/Spy.Ursnif.AJ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Ursnif.AJ virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Spy.Ursnif.AJ?


File Info:

crc32: 37E97286
md5: 0c1e5af9fbc1708f39827d182a7299e1
name: 0C1E5AF9FBC1708F39827D182A7299E1.mlw
sha1: ded8abcd66b125a5dabaeddb5ad344a95fd70447
sha256: 39578c5e2591778c92e9b64401377d3de02a108784d7fa0571424d229504db20
sha512: f8f88eedc71fafd7ab140b2a0d3e5cc9519bdfdd9db3eff2d0a978fb4917e5921dc90d2a33a718a663a0126aed2cbdd43f40201bf36000c45e6d8f2f2c1d322f
ssdeep: 3072:T7CrcUQDxPSJ0mIgpwZqs2YPCSdvp4F49PWoXTFKcQLb4zvZeGnxXvQb8hzH5/9:/vUQDxPi0m/pO2Y/Su9PWoXTFWLbqZe
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Win32/Spy.Ursnif.AJ also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 00507ec21 )
LionicTrojan.Win32.Papras.me4L
Elasticmalicious (high confidence)
DrWebTrojan.Packed.30345
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.813177
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Ursnif.6d44c264
K7GWSpyware ( 00507ec21 )
Cybereasonmalicious.9fbc17
CyrenW32/SecRisk-ProcessPatcher-base
SymantecBackdoor.Snifula.E
ESET-NOD32a variant of Win32/Spy.Ursnif.AJ
APEXMalicious
AvastSf:Crypt-IU [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.813177
NANO-AntivirusTrojan.Win32.Hijacker.gcbwdl
ViRobotTrojan.Win32.Z.Ursnif.191488
MicroWorld-eScanGen:Variant.Razy.813177
TencentWin32.Trojan.Hijacker.Eyo
Ad-AwareGen:Variant.Razy.813177
SophosMal/Generic-R + Mal/Zbot-U
BitDefenderThetaAI:Packer.921B19A91E
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.URSNIF.SMF
McAfee-GW-EditionBehavesLike.Win32.VirRansom.cc
FireEyeGeneric.mg.0c1e5af9fbc1708f
EmsisoftGen:Variant.Razy.813177 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Hijacker.Gen
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Generic.ASMalwS.2C72817
MicrosoftTrojanSpy:Win32/Ursnif.BM!MTB
ArcabitTrojan.Razy.DC6879
GDataGen:Variant.Razy.813177
AhnLab-V3Trojan/Win32.Ursnif.R150121
Acronissuspicious
McAfeeGenericATG-FCAE!0C1E5AF9FBC1
MAXmalware (ai score=86)
VBA32BScope.Trojan.Packed
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.Win32.URSNIF.SMF
RisingTrojan.Generic@ML.100 (RDML:+vrxg1g1n+yWPjhkXDJATQ)
YandexTrojan.GenAsa!cGU3PAmKJok
IkarusTrojan-Banker.UrSnif
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Papras.EH!tr
AVGSf:Crypt-IU [Trj]
Paloaltogeneric.ml

How to remove Win32/Spy.Ursnif.AJ?

Win32/Spy.Ursnif.AJ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment