Malware

Should I remove “Ser.Ursu.21729”?

Malware Removal

The Ser.Ursu.21729 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Ursu.21729 virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ser.Ursu.21729?


File Info:

crc32: 33B333DC
md5: 95d33fa8a5499c8f8191313e5b3dad26
name: 95D33FA8A5499C8F8191313E5B3DAD26.mlw
sha1: 22c78e3d7b09b8c267a4744543bcbc5d9064afb0
sha256: 8f12b040473833223152174aeaf99bd34330931a048b1788669559c3f56f2720
sha512: a5091a3f795c369a4284ffb0d6fc9dc44dd2bda85a2a4120da17cce549c5023cb5e5b10fe1302e7f12444c12e6ebee9598db541d9133ee6c5f53b9c150be6343
ssdeep: 192:do+3QaM+rO/GHmg5GJEIDfPf0D9/u//E89b0kKwJT7ZyBzu0gOMuMy:PrigmobIDfPMDQ//B9b0kvKBaz
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 1996-2018 VideoLAN and VLC Author
Assembly Version: 3.0.3.0
InternalName: grab.exe
FileVersion: 3.0.3.0
CompanyName: VLC media player
LegalTrademarks: VLC media player, VideoLAN and x264 are registered trademarks from VideoLAN
Comments: VLC media player
ProductName: VLC media player
ProductVersion: 3.0.3.0
FileDescription: VLC media player
OriginalFilename: grab.exe

Ser.Ursu.21729 also known as:

K7AntiVirusTrojan ( 0056a61a1 )
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ser.Ursu.21729
CAT-QuickHealTrojan.OccamyFC.S8705613
ALYacGen:Variant.Ser.Ursu.21729
MalwarebytesSpyware.ClipboardStealer.Generic
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/ClipBanker.73ba0e46
K7GWTrojan ( 0056a61a1 )
Cybereasonmalicious.8a5499
BitDefenderThetaGen:NN.ZemsilF.34050.am0@aC7JD7g
CyrenW32/ClipBanker.M.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/ClipBanker.LR
APEXMalicious
AvastWin32:DropperX-gen [Drp]
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderGen:Variant.Ser.Ursu.21729
NANO-AntivirusTrojan.Win32.ClipBanker.ieqqmb
TencentMsil.Trojan.Agent.Hvix
Ad-AwareGen:Variant.Ser.Ursu.21729
SophosMal/Generic-S
DrWebTrojan.PWS.Siggen.31367
ZillyaTrojan.ClipBanker.Win32.4077
McAfee-GW-EditionClipBanker-FCNX!95D33FA8A549
FireEyeGeneric.mg.95d33fa8a5499c8f
EmsisoftGen:Variant.Ser.Ursu.21729 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.opzc
AviraHEUR/AGEN.1136390
Antiy-AVLTrojan/Generic.ASMalwS.3037FBF
ArcabitTrojan.Ser.Ursu.D54E1
ZoneAlarmHEUR:Trojan.MSIL.Agent.gen
GDataMSIL.Trojan.ClipBanker.F
AhnLab-V3Malware/Win32.RL_Generic.C3622627
McAfeeClipBanker-FCNX!95D33FA8A549
MAXmalware (ai score=89)
VBA32TScope.Trojan.MSIL
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.MSIL.CLIPBANKER.SM
RisingSpyware.ClipBanker!1.D058 (CLASSIC)
IkarusTrojan.MSIL.ClipBanker
MaxSecureTrojan.Malware.8703358.susgen
FortinetMSIL/ClipBanker.MZ!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanDropper.Generic.HgIASOgA

How to remove Ser.Ursu.21729?

Ser.Ursu.21729 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment