Threat Database Trojans Trojan.Ursnif.Q

Trojan.Ursnif.Q

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 404
First Seen: April 6, 2022
Last Seen: December 29, 2025
OS(es) Affected: Windows

The detection of Trojan.Ursnif.Q on your system indicates a potential security threat that requires immediate attention. This report provides an overview of the threat, its operational characteristics, symptoms of infection, and steps to remove it from your system.

What Is Trojan.Ursnif.Q?

Trojan.Ursnif.Q is a type of malware that can compromise the security and integrity of your computer system. The name suggests it may be related to the Ursnif Trojan, known for its data theft capabilities, but without specific details, it's essential to focus on general removal and protection strategies. Malware like Trojan.Ursnif.Q can be designed to steal sensitive information, disrupt system operations, or provide unauthorized access to hackers.

How Trojan.Ursnif.Q Operates

Malware such as Trojan.Ursnif.Q typically operates by exploiting vulnerabilities in software or tricking users into installing it. Once installed, it can run in the background, hidden from the user, and perform various malicious activities. These can include data theft, keylogging, and the installation of additional malware. The exact operation can vary widely depending on the specific goals of the malware authors.

Symptoms of Infection

Symptoms of a Trojan.Ursnif.Q infection can be subtle and may not always be immediately apparent. Common signs include unusual system behavior, such as slow performance, unexpected pop-ups, or changes to browser settings. Users may also notice that their personal data is being stolen or that their system is being used for malicious activities without their knowledge. In some cases, the infection may not display any noticeable symptoms, making regular system checks crucial for early detection.

How to Remove Trojan.Ursnif.Q

  1. Enter Safe Mode with Networking to prevent the malware from loading and to allow for internet access to download removal tools. This can usually be done by restarting your computer and pressing a specific key (such as F8) during boot-up.
  2. Download and run a full scan with a reputable anti-malware tool, such as SpyHunter. Ensure the tool is updated to the latest version to increase the chances of detecting and removing the malware.
  3. Uninstall suspicious programs that were installed around the time the malware was detected. Be cautious and only remove programs you are certain are not needed or are known to be malicious.
  4. Reset your browsers (Chrome, Firefox, Edge, etc.) to their default settings to remove any malicious extensions or settings changes made by the malware.
  5. After completing the above steps, reboot your system and perform another scan with your anti-malware tool to ensure the malware has been fully removed.

Conclusion

Removing Trojan.Ursnif.Q from your system requires careful and immediate action to prevent further damage. By following the steps outlined above and maintaining good computer hygiene, such as regularly updating your operating system and applications, using strong antivirus software, and being cautious with emails and downloads, you can protect your system from similar threats in the future. Remember, prevention and vigilance are key to securing your digital environment.

Analysis Report

General information

Family Name: Trojan.Ursnif.Q
Signature status: No Signature

Known Samples

MD5: 1bb918e1eb7cdd6121b212fb6caef7dd
SHA1: 8f09d643c77f45614aa546c96f046dd183e1b2dc
SHA256: 5B8607FAF97E9DAB29BA6F9699E6D1E6CD59675458C4ABD00FFF218C0155DB4E
File Size: 868.35 KB, 868352 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Microsoft Corporation
File Description Microsoft® C Runtime Library
File Version 10.00.30319.1
Internal Name msvcr100_clr0400.dll
Legal Copyright © Microsoft Corporation. All rights reserved.
Original Filename msvcr100_clr0400.dll
Product Name Microsoft® Visual Studio® 2010
Product Version 10.00.30319.1

File Traits

  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 66
Potentially Malicious Blocks: 10
Whitelisted Blocks: 4
Unknown Blocks: 52

Visual Map

x ? x x ? ? ? ? 0 ? x x 2 ? x ? x ? x ? ? ? ? x ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? 0 ? ? ?
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\8f09d643c77f45614aa546c96f046dd183e1b2dc_0000868352.,LiQMAxHB

Related Posts

Trending

Most Viewed

Loading...