Adware

Should I remove “Adware.Ursu.340”?

Malware Removal

The Adware.Ursu.340 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Ursu.340 virus can do?

  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Adware.Ursu.340?


File Info:

crc32: FEB6D9BD
md5: e7170b2e625815401eb8db884f71f3f3
name: E7170B2E625815401EB8DB884F71F3F3.mlw
sha1: 75b803ae9c10a88c9ecbd3636cd2d1e4e147ace5
sha256: 1983bdb7e4127549023aa7951cb0db6a046a47d265999a7bab608b5d433390b8
sha512: aeaaaece248134b2bf7d4699155359b6666577ea6d16e4c2bc47f002efc4bdbd816db825756622219a940bd474c7e10ea647813b1d5ae883ee743861830e5356
ssdeep: 98304:+qnC5WNuqbyGK6B0GwuYicSOsif7E/VEx1Ac2:jnCgN/yGKE5Ofx1f2
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: x6e56x5317x5965x6e38x4fe1x606fx79d1x6280x6709x9650x516cx53f8 aoukj.com
FileVersion: 1.4.0.0
CompanyName: x6e56x5317x5965x6e38x4fe1x606fx79d1x6280x6709x9650x516cx53f8
ProductName: x94c1x7532x9632x706bx5899
ProductVersion: 1.4
FileDescription: x94c1x7532x9632x706bx5899 x5ba2x6237x7aef
Translation: 0x0409 0x04e4

Adware.Ursu.340 also known as:

BkavW32.AIDetect.malware2
DrWebTrojan.SkypeSpam.11168
CynetMalicious (score: 99)
ALYacGen:Variant.Adware.Ursu.340
ZillyaBackdoor.Poison.Win32.88318
SangforBackdoor.Win32.Poison.jedt
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaBackdoor:Win32/Poison.1daf3d42
Cybereasonmalicious.e62581
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/RiskWare.GameTool.N
APEXMalicious
AvastWin32:Evo-gen [Susp]
KasperskyBackdoor.Win32.Poison.jedt
BitDefenderGen:Variant.Adware.Ursu.340
NANO-AntivirusTrojan.Win32.Poison.exoida
MicroWorld-eScanGen:Variant.Adware.Ursu.340
TencentWin32.Backdoor.Poison.Aihr
Ad-AwareGen:Variant.Adware.Ursu.340
SophosGeneric PUA HF (PUA)
BitDefenderThetaGen:NN.ZelphiF.34266.jpKfaCjlk6el
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0OJV21
McAfee-GW-EditionBehavesLike.Win32.AdwareIMonster.wc
FireEyeGen:Variant.Adware.Ursu.340
EmsisoftGen:Variant.Adware.Ursu.340 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1111514
Antiy-AVLTrojan/Generic.ASMalwS.23D2B3A
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataGen:Variant.Adware.Ursu.340
McAfeeArtemis!E7170B2E6258
MAXmalware (ai score=69)
VBA32Backdoor.Poison
TrendMicro-HouseCallTROJ_GEN.R002C0OJV21
YandexTrojan.GenAsa!2uXp6ojDGn8
IkarusBackdoor.Win32.Poison
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic_PUA_HF
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml

How to remove Adware.Ursu.340?

Adware.Ursu.340 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment