Malware

Ser.Ursu.12885 malicious file

Malware Removal

The Ser.Ursu.12885 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Ursu.12885 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Exhibits behavior characteristic of Pony malware
  • Exhibits possible ransomware file modification behavior
  • Collects information about installed applications
  • Creates a hidden or system file
  • Harvests credentials from local FTP client softwares
  • Attempts to create or modify system certificates

Related domains:

repository.certum.pl
subca.ocsp-certum.com
crl.certum.pl
ocsp.certum.pl

How to determine Ser.Ursu.12885?


File Info:

crc32: 0B011221
md5: 3bdeb408b010af2606eb2f10f3e8bd29
name: solo.exe
sha1: 430305f3bc19b62b5b7743f6629c03900a9235b7
sha256: 7ebb498e246d0260bd8555418b1966a7c40e2a3b54ab215020851096c6d7574d
sha512: 2e7622805a34e47a6b48f6a1b6e0e30fc632250aed961feef4516b43cf91995a83a3714b47b00ce7b40e3e01a8a0b6cc9ffc750d246695b4adfeedaa47363b1c
ssdeep: 1536:FbeyL75HDWNujtw32kyJb0y4FhLYZDYMtYSrXl/F/vmNZr/YF7gG2AGl2s:Fqyn5HKNujvHKFORYWN5RekkFys
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: solo.exe
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename: solo.exe

Ser.Ursu.12885 also known as:

MicroWorld-eScanGen:Variant.Ser.Ursu.12885
FireEyeGeneric.mg.3bdeb408b010af26
McAfeeTrojan-FGZT!3BDEB408B010
CylanceUnsafe
BitDefenderGen:Variant.Ser.Ursu.12885
Cybereasonmalicious.3bc19b
TrendMicroTROJ_GEN.R002C0PD620
APEXMalicious
AvastWin32:Evo-gen [Susp]
GDataGen:Variant.Ser.Ursu.12885
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:MSIL/Injector.52737c27
AegisLabTrojan.Win32.Generic.4!c
TencentWin32.Trojan.Falsesign.Lnys
Endgamemalicious (high confidence)
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1029322
DrWebTrojan.PWS.Stealer.13311
Invinceaheuristic
McAfee-GW-EditionTrojan-FGZT!3BDEB408B010
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Ser.Ursu.12885 (B)
IkarusTrojan.Crypt
CyrenW32/Trojan.VDYS-6283
JiangminTrojan/PSW.Fareit.fsa
AviraHEUR/AGEN.1029322
MAXmalware (ai score=88)
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Ser.Ursu.D3255
ZoneAlarmHEUR:Trojan.Win32.Generic
BitDefenderThetaGen:NN.ZemsilF.34106.im1@ayd@P5f
VBA32TrojanPSW.Fareit
PandaTrj/CI.A
ESET-NOD32a variant of MSIL/Injector.LCE
RisingStealer.Pony!8.10FE4 (CLOUD)
SentinelOneDFI – Malicious PE
eGambitPE.Heur.InvalidSig
FortinetMSIL/Injector.KZF!tr
Ad-AwareGen:Variant.Ser.Ursu.12885
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (W)
Qihoo-360Generic/HEUR/QVM03.0.620B.Malware.Gen

How to remove Ser.Ursu.12885?

Ser.Ursu.12885 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment