TrojanSpy: Win32/Ursnif.HM Removal Guide – Method to Remove TrojanSpy: Win32/Ursnif.HM


"TrojanSpy: Win32/Ursnif.HM has infected my Windows computer very badly and my anti virus is not able to wipe out this infection completely. The Windows operating system has been rapidly losing is performance ability, stability and speed. Due to activation of TrojanSpy: Win32/Ursnif.H, the PC become very sluggish and showing tendency of corruption. What should I do for effective removal of TrojanSpy: Win32/Ursnif.HM virus on my Windows machine

TrojanSpy: Win32/Ursnif.HM is a new variant of Trojan horse virus which has ability to misapply far famed websites to send Spam emails on the mail account of Internet users and the event to open the email and to view attachment issue commands to execute the Trojan virus on targeted computer. The features of this Trojan is quite different from various other malware it uses RAT (Remote Administrator Tool) to misuse Component Object model (COM) interface to install plug-in to stick on Windows web browsers. This process allow malicious program to stay on your system without notice by user or detection as a threat by anti virus program. TrojanSpy: Win32/Ursnif.HM may also enters on your computer with other free software application or updates as an an additional program and execute itself in the background without any consent or permission of computer owner.

IT security experts strongly recommends to eliminate TrojanSpy: Win32/Ursnif.HM Trojan virus from your computer as soon as you find symptoms of infection. Because the Trojan horse is designed to completely ruin your computer in all aspects. It block all the security tools on your computer like Windows Firewall and anti virus program which makes your computer very unsure and irresistible against invasion of other malware and viruses. It modify system registry and web browser settings to monitor user's Internet activities and collect confidential information like email ID, password, online bank account details, etc. The extreme exploitation of system resources like CPU, RAM, Hard disk space and Internet connection by this Trojan virus to regularly communicate with remote server, upload/download files, spreading malicious mails and creation of junk files on your computer lead your system very sluggish and even pervert to corruption. Hence you should take quick initiatives to remove TrojanSpy: Win32/Ursnif.HM from your computer as soon as possible by following removal steps in this post.


Steps to Remove TrojanSpy: Win32/Ursnif.HM

Step 1>> How to Boot Windows in Safe Mode to isolate TrojanSpy: Win32/Ursnif.HM

Step 2>> How to View Hidden Files created by TrojanSpy: Win32/Ursnif.HM

for Windows XP

  • Exit all Program and Go to Desktop
  • Select My Computer icon and Double Click to Open it
  • Click on the Tools Menu and now select and Click on Folder Options.
  • Select on View Tab that appears in New Window.
  • Check mark on the box next to Dispaly the Contents of System Folders
  • Now Check the box in order to Show Hidden Files and Folders
  • Now press on Apply and OK to close the Window.
  • As soon as these steps are performed, you can view the files and folders that were created by TrojanSpy: Win32/Ursnif.HM and hidden till now.

Win xp 2


for Windows Vista

  • Minimize all Window and Go to Desktop
  • Click on the Start Button which can be found in lower lef Corner having Windows Logo
  • Click on the Control Panel on the Menu and Open it
  • Control Panel can be opened in Classic View or Control Panel Home View.
  • If you have Selected Classic View, follow this
  • Double Click on the Folder icon to open it
  • Now select the view tab
  • Click on Option to Show Hidden Files or Folders
  • If you have Selected Control Panel Home View, follow this
  • Appearance and Personalization link is to be Clicked
  • Select on Show Hidden Files or Folders
  • Press Apply Option and then Click on OK.


This will Show all the Folders including those created by TrojanSpy: Win32/Ursnif.HM

Know how to view Hidden Folders on Windows 7, Win 8 and Windows 10

(Following the above steps are necessary to view all the files created by TrojanSpy: Win32/Ursnif.HM and that is known to exist on Compromised PC.)

  • Open the Run Box by holding together the Start Key and R.



  • Now Type and input appwiz.cpl and press on OK
  • This will take you to the Control Panel, Now Search for Suspicious programs or any entries related to TrojanSpy: Win32/Ursnif.HM. Unistall it once if you happen to find it. However be sure not to Uninstall any other program from the list.
  • In the Search Field, Type msconfig and press on Enter, this will pop-up a Window


In the Startup Menu, Uncheck all the TrojanSpy: Win32/Ursnif.HM related entries or which are Unknown as Manufacturer.

Step 3>> Open the Run Box by Pressing Start Key and R in Combination


  1. Copy + Paste the following Command as
  2. notepad %windir%/system32/Drivers/etc/hosts and press on OK
  3. This will Open a new file. If your system has been hacked by TrojanSpy: Win32/Ursnif.HM, certain IP’s will be displayed which can be found in the bottom of the screen.


Look for the suspicious IP that is present in your Localhost

Step 4>> How to Terminate TrojanSpy: Win32/Ursnif.HM Running Processes

  • Go the Processes Tab by pressing on CTRL+SHIFT+ESC Keys Together.
  • Look for the TrojanSpy: Win32/Ursnif.HM Running Processes.
  • Right Click on TrojanSpy: Win32/Ursnif.HM and End the Process.


Step 5>> How to Remove TrojanSpy: Win32/Ursnif.HM Related Registry Entries

  • Open Registry by Typing Regedit in the Run box and Hit Enter Key


  • This will open all the list of entries.
  • Now Find and search the entries created by TrojanSpy: Win32/Ursnif.HM and cautiously delete it.
  • Alternatively, you can manually search for it in the list to delete TrojanSpy: Win32/Ursnif.HM Manually.

Unfortunately, if you are unable to remove TrojanSpy: Win32/Ursnif.HM, Scan your PC Now



Also submit question and let us know in case you are having some doubt. Our Experts will definitely respond with some positive suggestions for the same. Thanks!