Malware

Ser.Ursu.20697 removal guide

Malware Removal

The Ser.Ursu.20697 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Ursu.20697 virus can do?

  • Creates RWX memory
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

How to determine Ser.Ursu.20697?


File Info:

crc32: 3D1FA40C
md5: 58c55a27d668a8b8dcef2616cb0419b9
name: 58C55A27D668A8B8DCEF2616CB0419B9.mlw
sha1: b4286b89bd9eb0c38f9bfecf88875a73aba166c7
sha256: 1dcd3fcf8cc65ce859e6eecb35987228d910dcfe53d096d4fd8b7a3ad3a9d958
sha512: ed04ca7cf3638bb85ccf873995dd6fba56626d665efeefb83c0d7c536ec7c289f9838c9a9da43e6ddea69755509ff0d3146f4e9450affb2d2b11885a2fec28cf
ssdeep: 24576:mTZVuEMmqm/PhfhBPS918WAE1ZVeTz3Q8+GX5nsakRhTcw:h0tSvA+VeTD5nKTR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ser.Ursu.20697 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 7000000f1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ser.Ursu.20697
CylanceUnsafe
ZillyaTrojan.Delf.Win32.58090
SangforTrojan.Win32.GenMalicious.ABK
AlibabaTrojanPSW:Win32/FakeMSN.f42b1cf0
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.7d668a
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/PSW.FakeMSN.NCJ
APEXMalicious
AvastWin32:GenMalicious-ABK [Trj]
KasperskyTrojan-PSW.Win32.Delf.hew
BitDefenderGen:Variant.Ser.Ursu.20697
NANO-AntivirusTrojan.Win32.MlwGen.ejmqmq
MicroWorld-eScanGen:Variant.Ser.Ursu.20697
TencentWin32.Trojan-qqpass.Qqrob.Syif
Ad-AwareGen:Variant.Ser.Ursu.20697
SophosMal/Generic-S
ComodoMalware@#3kjose8jhallj
BitDefenderThetaGen:NN.ZelphiF.34266.TPW@aunrX7oO
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Generic.th
FireEyeGeneric.mg.58c55a27d668a8b8
EmsisoftGen:Variant.Ser.Ursu.20697 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/ATRAPS.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.18939FA
MicrosoftTrojanSpy:Win32/Skeeyah.A!rfn
GDataGen:Variant.Ser.Ursu.20697
McAfeeGenericR-HMB!58C55A27D668
MAXmalware (ai score=99)
VBA32TrojanPSW.Delf
MalwarebytesMalware.AI.1207433716
PandaTrj/CI.A
RisingTrojan.Generic@ML.82 (RDML:ORfIUFSHAdovcrwS/jKg8A)
YandexTrojan.GenAsa!RkjT8wn3UoQ
IkarusTrojan-Dropper.Delf
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/FakeMSN.NCI!tr
AVGWin32:GenMalicious-ABK [Trj]
Paloaltogeneric.ml

How to remove Ser.Ursu.20697?

Ser.Ursu.20697 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment