Malware

Mal/Generic-S + Troj/Ursnif-EO removal tips

Malware Removal

The Mal/Generic-S + Troj/Ursnif-EO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-S + Troj/Ursnif-EO virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Uses Windows utilities for basic functionality
  • A process attempted to delay the analysis task by a long amount of time.
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Mal/Generic-S + Troj/Ursnif-EO?


File Info:

crc32: 22D10113
md5: bae60f2c8a14eb4bb86366508a86092f
name: BAE60F2C8A14EB4BB86366508A86092F.mlw
sha1: 8639495ce72130151b0fd2c56366de993015c09b
sha256: a75252b275cb4e2aca95cb4e2d2b6bbb1f9bac373daf21724f0424026194e856
sha512: 450950b54561f12b72e8172efc044330c5fdb17b111c3c9a26b07866b1caf7ec4cb9903f17f78145d62769ca819396db66d2f9078c2319f0891491ad0a9e6c56
ssdeep: 12288:QxHGz7jrsxOZWGvw2uV+HZfyWdAHKHRfhtOJbIP5UsT9GdOxRCeg:jtWGvCV+5QoVhPNT961eg
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Order 1995-2019
FileVersion: 0.1.5.767
CompanyName: Order
ProductName: Race rise
ProductVersion: 0.1.5.767
FileDescription: Race rise
OriginalFilename: camp.dll
Translation: 0x0409 0x04e4

Mal/Generic-S + Troj/Ursnif-EO also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Gozi.796
CynetMalicious (score: 90)
ALYacTrojan.GenericKDZ.73567
CylanceUnsafe
SangforTrojan.Win32.Wacatac.B
AlibabaTrojanSpy:Win32/Ursnif.817a8b50
K7GWSpyware ( 0053a1971 )
K7AntiVirusSpyware ( 0053a1971 )
CyrenW32/Kryptik.DQI.gen!Eldorado
ESET-NOD32Win32/Spy.Ursnif.BX
APEXMalicious
AvastWin32:BankerX-gen [Trj]
BitDefenderTrojan.GenericKDZ.73567
MicroWorld-eScanTrojan.GenericKDZ.73567
Ad-AwareTrojan.GenericKDZ.73567
SophosMal/Generic-S + Troj/Ursnif-EO
ComodoTrojWare.Win32.Agent.taczr@0
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_FRS.0NA103CI21
McAfee-GW-EditionTrojan-FRGC!BAE60F2C8A14
FireEyeTrojan.GenericKDZ.73567
EmsisoftTrojan.GenericKDZ.73567 (B)
AviraTR/AD.UrsnifDropper.dqyyh
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Gozi.GT!MTB
ArcabitTrojan.Generic.D11F5F
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.GenericKDZ.73567
AhnLab-V3Trojan/Win32.GenericKD.C4382849
McAfeeTrojan-FRGC!BAE60F2C8A14
MAXmalware (ai score=83)
MalwarebytesSpyware.Ursnif
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_FRS.0NA103CI21
RisingSpyware.Ursnif!8.1DEF (CLOUD)
IkarusTrojan-Spy.Agent
FortinetW32/Banker.X!tr
AVGWin32:BankerX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanPSW.Gozi.HgkASRAA

How to remove Mal/Generic-S + Troj/Ursnif-EO?

Mal/Generic-S + Troj/Ursnif-EO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment