Threat Database Trojans Trojan.Ursu.B

Trojan.Ursu.B

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 17,309
Threat Level: 80 % (High)
Infected Computers: 7
First Seen: November 19, 2025
Last Seen: July 17, 2026
OS(es) Affected: Windows

The detection of Trojan.Ursu.B on your system indicates a potential security threat that requires immediate attention. This detection name suggests a type of malicious software, but without more specific information, it's crucial to understand the general characteristics of such threats and how to mitigate them. In this report, we will guide you through the nature of Trojan.Ursu.B, its operational methods, symptoms of infection, removal procedures, and preventive measures to ensure your system's security.

What Is Trojan.Ursu.B?

Trojan.Ursu.B, as indicated by its name, falls under the category of Trojan horses, which are malicious programs that disguise themselves as legitimate software. These types of malware can allow unauthorized access to a computer system, enabling the perpetrator to steal sensitive information, install additional malware, or disrupt system operations. The name Trojan.Ursu.B itself does not specify a known malware family but suggests a variant or specific strain of Trojan horse malware.

How Trojan.Ursu.B Operates

Trojan horses like Trojan.Ursu.B typically operate by deceiving users into installing them, often by masquerading as useful applications or piggybacking on legitimate software downloads. Once installed, they can create backdoors for remote access, allowing attackers to execute commands, steal data, or install more malware. The specific operations of Trojan.Ursu.B can vary, but the general goal is to compromise system security and exploit user data without detection.

Symptoms of Infection

Symptoms of a Trojan.Ursu.B infection can be subtle and may include unusual system behavior such as slow performance, frequent crashes, or pop-ups and unwanted software installations. Users may also notice unauthorized changes to their system settings or suspicious network activity. However, some Trojans are designed to operate stealthily, making them difficult to detect without proper security software.

How to Remove Trojan.Ursu.B

  1. Enter Safe Mode with Networking to limit the malware's ability to interfere with the removal process. This mode allows you to use the internet to download removal tools while minimizing system processes.
  2. Conduct a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all traces of Trojan.Ursu.B and any related malware.
  3. Uninstall suspicious programs that you do not recognize or that were installed around the time the malware was detected. Be cautious and ensure you are removing the correct programs to avoid disrupting your system's functionality.
  4. Reset your browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot your system and perform another scan with your anti-malware tool to ensure that all components of the Trojan have been removed and that your system is clean.

Conclusion

The detection and removal of Trojan.Ursu.B require careful attention to detail and a systematic approach to ensure that all traces of the malware are eliminated. By understanding the nature of Trojan horses and following the steps outlined in this report, you can effectively remove Trojan.Ursu.B from your system and take proactive measures to prevent future infections. Regularly updating your security software, being cautious with downloads, and maintaining good browsing habits are key to protecting your system against evolving malware threats.

Analysis Report

General information

Family Name: Trojan.Ursu.B
Signature status: Hash Mismatch

Known Samples

MD5: 807d442e33cd5ec3e504c33c9652fe95
SHA1: a7306e88d7b5da1385a455edec4eef1f4869e34d
SHA256: 87FFA9F8593F8BCA690AA33C3AE9382E23940B1B35B8483D2EA8333DDF2034BE
File Size: 827.10 KB, 827096 bytes
MD5: 55bb029fb7339540a0f58d1c8d8a42a5
SHA1: 009054214f8d7e81f584d0eb634e61cbdae536bf
SHA256: ADA60B4B171ED5DE5B8C75B2FB2D29E72EB9C037ECE7CF45AA2A8DD8F429B0A1
File Size: 823.30 KB, 823296 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name Roblox Corporation
File Description Roblox
File Version
  • 1, 6, 3, 166809
  • 1, 6, 3, 163458
Legal Copyright (C) 2012 Roblox Corporation. All rights reserved.
Original Filename Roblox.exe
Product Name Roblox Bootstrapper
Product Version 1, 6, 3, 0

Digital Signatures

Signer Root Status
Roblox Corporation Symantec Class 3 Extended Validation Code Signing CA - G2 Hash Mismatch
Roblox Corporation thawte SHA256 Code Signing CA Hash Mismatch

File Traits

  • HighEntropy
  • x86

Block Information

Total Blocks: 2,859
Potentially Malicious Blocks: 475
Whitelisted Blocks: 2,383
Unknown Blocks: 1

Visual Map

0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 x x x x x x x x 0 0 0 x 0 x 0 0 0 0 0 0 0 x x 0 x x 0 0 x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 x 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x 0 x x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 0 x x 0 0 x x 0 0 0 0 0 0 0 x x x x 0 0 0 0 0 x 0 x 0 0 0 0 0 x x x x x 0 0 0 0 0 0 x 0 0 0 0 0 x 0 0 x 0 0 x x 0 x x 0 1 x x x x 1 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x 0 x x 0 0 x 0 x x 0 x x x 0 x x x 0 0 x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x 0 0 0 0 0 x x 0 0 0 0 0 0 x x x 0 x x x x x x x x 0 0 x x 0 x x 0 0 x 0 0 0 x x 0 0 0 0 0 0 x 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 x 0 0 0 x x 0 x 0 1 1 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 x x x x x x x x 0 x 0 x x x 0 0 x x x x 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 x x 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 x x x x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 x 0 0 x x x x x x 0 0 x 0 0 0 0 x 0 0 x 0 x x x x x 0 x 0 0 0 0 x 0 x x x x x 0 0 0 x x x x x x x 0 x 0 x x 0 x x x x 0 0 x x x x 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 0 x 0 x 0 0 0 x x x x 0 0 0 0 1 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 ? 0 0 x x x x 0 x 0 x 0 0 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 x x x 0 x 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x x x x 0 0 x 0 0 0 0 0 0 0 0 x x x 0 x 0 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x 0 0 0 0 x x x x 0 x x 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x 0 0 0 x 0 0 0 x 0 x x x 0 x 0 0 0 0 0 x x x x x x x x 0 0 x x x x x 0 0 0 0 x x x 0 x 0 0 0 x x 0 0 0 0 x 0 0 0 0 0 x x 0 0 0 0 x x 0 x 0 0 0 x 0 x 0 x 0 x 0 x x x 0 0 x 0 x 0 0 0 0 0 0 x x x x x x x x 0 0 x x x x x x x x x 0 0 0 0 0 x x 0 x 0 x 0 x 0 x 0 x x x x 0 x x x x x 0 0 0 x x 0 x 0 0 0 x x x x x 0 x x x 0 0 0 x x 0 0 x x x x 0 x 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 x 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x x x x 0 0 0 0 0 0 x 0 x 0 0 0 0 0 x x x x x x x x x x x x 0 x 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x x x x 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 x x 0 x 0 x x 0 0 0 x 0 0 0 x 0 x x x x x x x x x x 0 x x 0 0 x 0 x x 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 x x 0 0 0 0 0 x 0 0 0 x 0 0 0 0 x x 0 0 0 0 0 0 0 0 x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 1 1 0 0 0 0 1 1 1 1 0 2 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 1 1 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Ursu.B
  • Ursu.BF

Files Modified

File Attributes
c:\users\user\appdata\local\temp\rbx-014de9cc.log Generic Write,Read Attributes
c:\users\user\appdata\local\temp\rbx-71a2f043.log Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\roblox corporation\roblox::cpath C:\Users\user\AppData\LocalLow\rbxcsettings.rbx RegNtPreCreateKey

Windows API Usage

Category API
Network Winsock2
  • WSAStartup
Network Info Queried
  • GetAdaptersInfo
Network Wininet
  • HttpOpenRequest
  • HttpSendRequest
  • InternetConnect
  • InternetOpen
  • InternetSetOption
Network Winhttp
  • WinHttpOpen

Trending

Most Viewed

Loading...