Ransom

About “Ransom:Win32/Urausy.E” infection

Malware Removal

The Ransom:Win32/Urausy.E is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Urausy.E virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ransom:Win32/Urausy.E?


File Info:

crc32: 85668F49
md5: cf8fdbfe1a382025c6953ec2f04889c8
name: CF8FDBFE1A382025C6953EC2F04889C8.mlw
sha1: 2d15e052ef024e2b1250dc7cceb04d7a436eb5b0
sha256: e1c4d6b0956273a4746c7be569cacebcdf0497e178f7c7b9c7a61c01ddf79e36
sha512: 4c236b8bd67ae06781ca001cd338fcbfde6e7cbed79374d268e72b242c548b539e268ca2070b72f115ed19fde85928762d04af4177adb5285fc43de98e687fb3
ssdeep: 768:9PFCoWTUDrzmpH9GE925OrmaNctd1zSLOqMdlVKveSLcm+jbOZCgk:9PFCodPm19GEUydLOqMdWvWm+XGC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Urausy.E also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ser.Mikey.1185
CAT-QuickHealTrojan.Urausy.C
Qihoo-360Generic/HEUR/QVM20.1.Malware.Gen
ALYacGen:Variant.Ser.Mikey.1185
CylanceUnsafe
VIPRELooksLike.Win32.Uruasy.a!ag (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040f5ef1 )
BitDefenderGen:Variant.Ser.Mikey.1185
K7GWTrojan ( 0040f5ef1 )
Cybereasonmalicious.e1a382
CyrenW32/S-71dc1b3f!Eldorado
SymantecTrojan.Ransomlock!g55
ESET-NOD32Win32/LockScreen.AQD
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Zusy-9754221-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.RiskGen.cqkupp
SUPERAntiSpywareTrojan.Agent/Gen-Urausy
TencentMalware.Win32.Gencirc.10bf87c0
Ad-AwareGen:Variant.Ser.Mikey.1185
EmsisoftGen:Variant.Ser.Mikey.1185 (B)
ComodoApplication.Win32.AdWare.SystemSecurity.S@51rcsx
F-SecureTrojan.TR/Ransom.98304512
DrWebTrojan.Winlock.9260
TrendMicroTROJ_URAUSY.SMX
McAfee-GW-EditionRansom-FAV!CF8FDBFE1A38
FireEyeGeneric.mg.cf8fdbfe1a382025
SophosML/PE-A + Mal/Katusha-U
IkarusTrojan.Win32.Yakes
GDataGen:Variant.Ser.Mikey.1185
JiangminTrojan/Foreign.odz
WebrootW32.Rogue.Gen
AviraTR/Ransom.98304512
MAXmalware (ai score=86)
Antiy-AVLTrojan[Ransom]/Win32.Foreign
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ArcabitTrojan.Ser.Mikey.D4A1
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftRansom:Win32/Urausy.E
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Foreign.R78901
McAfeeRansom-FAV!CF8FDBFE1A38
TACHYONTrojan/W32.Foreign.98304.YP
VBA32BScope.Malware-Cryptor.Hlux
MalwarebytesTrojan.Agent
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_URAUSY.SMX
RisingRansom.Urausy!8.2B7 (TFE:dGZlOgKlC1NYNqO+zQ)
YandexTrojan.GenAsa!sQsWD92v78M
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_73%
FortinetW32/Yakes.DBUS!tr
BitDefenderThetaGen:NN.ZexaF.34590.guW@aqDstnoi
AVGWin32:Urausy-AH [Trj]
AvastWin32:Urausy-AH [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Ransom:Win32/Urausy.E?

Ransom:Win32/Urausy.E removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment