Threat Database Trojans Trojan.Ursnif.H

Trojan.Ursnif.H

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 6
First Seen: November 14, 2012
Last Seen: November 8, 2025
OS(es) Affected: Windows

The detection of Trojan.Ursnif.H on your system indicates a potential security threat that requires immediate attention. This type of malware is designed to compromise the security and integrity of your computer, and it's essential to understand its nature and take steps to remove it.

What Is Trojan.Ursnif.H?

Trojan.Ursnif.H is a type of Trojan horse malware, which means it is a malicious program that disguises itself as a legitimate application. The name "Trojan.Ursnif.H" suggests that it may be related to the Ursnif malware family, but without further information, it's difficult to determine the exact nature of this threat. Generally, Trojans are designed to allow unauthorized access to a computer system, and they can be used to steal sensitive information, install additional malware, or disrupt system operations.

How Trojan.Ursnif.H Operates

Trojan.Ursnif.H, like other Trojans, operates by exploiting vulnerabilities in software or tricking users into installing it. Once installed, it can create a backdoor that allows remote access to the infected computer. This backdoor can be used to download and install additional malware, steal sensitive information, or disrupt system operations. The malware may also be designed to evade detection by traditional antivirus software, making it challenging to remove.

Symptoms of Infection

Infected computers may exhibit a range of symptoms, including slow performance, frequent crashes, and unusual network activity. Users may also notice that their computer is behaving erratically, such as displaying unfamiliar error messages or launching unexpected applications. In some cases, the malware may attempt to steal sensitive information, such as login credentials or financial data, which can lead to identity theft or financial loss.

  • Unexplained changes to system settings or configuration
  • Appearance of unfamiliar programs or icons
  • Increased network activity or unusual traffic patterns
  • Slow system performance or frequent crashes

How to Remove Trojan.Ursnif.H

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for internet access.
  2. Run a full scan with a reputable anti-malware tool, such as SpyHunter, to detect and remove the malware.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and run another full scan to ensure that the malware has been completely removed.

Conclusion

Removing Trojan.Ursnif.H from your system requires careful attention to detail and a thorough understanding of the malware's behavior. By following the steps outlined above and using reputable anti-malware tools, you can help to ensure that your computer is free from this threat. It's essential to remain vigilant and take steps to prevent future infections, such as keeping your operating system and software up to date, using strong passwords, and avoiding suspicious downloads or email attachments.

Analysis Report

General information

Family Name: Trojan.Ursnif.H
Signature status: Hash Mismatch

Known Samples

MD5: aa3e38c5fb31bd497afe4b929cbbb63b
SHA1: 1dbc887564e01fd901f60e332b6511c6d389b96a
SHA256: D7BEAC1D74BA5EE6E5E2668C1BA21D9F8A6B47D17D4CDC03EEABB0B7A278238D
File Size: 317.48 KB, 317479 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Adobe Systems Incorporated
File Description CCLibraries
File Version 2.11.0.966
Internal Name CCLibraries
Legal Copyright Copyright 2015-2017 Adobe Systems Incorporated. All rights reserved.
Original Filename CCLibraries.exe
Product Name CCLibraries
Product Version 2.11.0.966

Digital Signatures

Signer Root Status
Adobe Systems Incorporated Symantec Class 3 Extended Validation Code Signing CA - G2 Hash Mismatch

File Traits

  • big overlay
  • HighEntropy
  • x86

Block Information

Total Blocks: 572
Potentially Malicious Blocks: 10
Whitelisted Blocks: 531
Unknown Blocks: 31

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 ? ? 0 0 0 ? ? 0 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 ? ? 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? ? 0 ? 0 0 0 x 0 0 0 0 ? ? x x 0 0 0 x x 0 ? 0 ? ? 0 ? 0 0 ? ? x ? x x ? ? x x ? ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 1 1 0 0 0 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 1 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 3 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 2 2 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\program files\common files\system\symsrv.dll Generic Write,Read Attributes
c:\users\user\appdata\local\temp\creativecloud\creative cloud libraries\cc library process.log Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\windows nt\currentversion\windows::appinit_dlls C:\PROGRA~1\COMMON~1\System\symsrv.dll RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows nt\currentversion\windows::loadappinit_dlls  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows nt\currentversion\windows::requiresignedappinit_dlls RegNtPreCreateKey

Windows API Usage

Category API
Process Shell Execute
  • CreateProcess

Shell Command Execution

"c:\users\user\downloads\libs\node.exe" "c:\users\user\downloads\js\server.js"

Related Posts

Trending

Most Viewed

Loading...