Malware

Application.Ursu.327112 malicious file

Malware Removal

The Application.Ursu.327112 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Ursu.327112 virus can do?

  • Attempts to connect to a dead IP:Port (8 unique times)
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Attempts to modify proxy settings

Related domains:

dlsft.com
media.discordapp.net
dpd.securestudies.com
x.ss2.us
ocsp.digicert.com
o.ss2.us
ocsp.rootg2.amazontrust.com
ocsp.rootca1.amazontrust.com
ocsp.sca1b.amazontrust.com

How to determine Application.Ursu.327112?


File Info:

crc32: E56AE712
md5: 5590814d7a87bbad2bd4f3a1306eef4a
name: 5590814D7A87BBAD2BD4F3A1306EEF4A.mlw
sha1: 8ca09b0660b29d6cb8ece5e23abe80ad0f929260
sha256: 1a2e51617a6263e393a3c02fbe1c95081b96a7722e407a03628683ea6a8f0572
sha512: 63bbaaa18fd160b3142f25a632103ee830644a38ff980246fb653f6b713baeb253206f4edd61c6c1f453d6759a9336e6754bd3299221d231603e0b3c071ecfe5
ssdeep: 98304:2N9OhMhiXkL20DsCVHUrqNBRHfJwc0PT8:2PZhiXkLl0rqNPfUr8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Installer C
InternalName: Installer AB
FileVersion: 1
ProductName: Installer C
ProductVersion: 1
FileDescription: Installer C
OriginalFilename: Installer AB
Translation: 0x0409 0x04b0

Application.Ursu.327112 also known as:

K7AntiVirusAdware ( 00552da41 )
LionicTrojan.Win32.Mikey.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader27.12424
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericPMF.S3846157
ALYacGen:Variant.Application.Ursu.327112
CylanceUnsafe
AlibabaAdWare:Win32/InstallUnion.de92b47a
K7GWAdware ( 00552da41 )
Cybereasonmalicious.d7a87b
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.InstallUnion.A
APEXMalicious
AvastWin32:Malware-gen
Kasperskynot-a-virus:HEUR:Downloader.Win32.Agent.gen
BitDefenderGen:Variant.Application.Ursu.327112
NANO-AntivirusRiskware.Win32.Techsnab.fngher
MicroWorld-eScanGen:Variant.Application.Ursu.327112
Ad-AwareGen:Variant.Application.Ursu.327112
SophosMal/Generic-S
ComodoMalware@#3nvdciqdudkus
BitDefenderThetaGen:NN.ZexaF.34236.@F1@amKopInO
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.rh
FireEyeGeneric.mg.5590814d7a87bbad
EmsisoftGen:Variant.Application.Ursu.327112 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
Antiy-AVLTrojan/Generic.ASMalwS.28B78A3
MicrosoftTrojan:Win32/Occamy.C
GDataGen:Variant.Application.Ursu.327112
AhnLab-V3PUP/Win32.DownloadHelper.R240919
McAfeeArtemis!5590814D7A87
MAXmalware (ai score=94)
MalwarebytesAdware.DownloadHelper
RisingTrojan.Generic@ML.95 (RDML:Fafm68uc5sy8srpFkHwggw)
YandexTrojan.GenAsa!2exPQ4fEsIQ
IkarusAdWare.FileFinder
FortinetAdware/FILEFINDER
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Application.Ursu.327112?

Application.Ursu.327112 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment