Malware

Ser.Ursu.22998 information

Malware Removal

The Ser.Ursu.22998 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Ursu.22998 virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Unusual version info supplied for binary

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ser.Ursu.22998?


File Info:

crc32: 99E2B84C
md5: 8265cda4525102a1759289e36a98aeb4
name: 8265CDA4525102A1759289E36A98AEB4.mlw
sha1: 2cf1963980d5c3fc0c14f11d1e8d609fb20b033d
sha256: 6c9a5ec60bbe3d2422fe012c35640eda86adb134c2213e803fde73960bd88f57
sha512: f9af32adee9a7bc82dc8f7a7531dcdf0f9f5904acf7cde838734cbec2b605c3dc079aad93ed5d061213bda4cfc826cb373e40c6230377df5310135f2ef740f94
ssdeep: 192:OLRR8f4D1WPrVVEbth33xkNzjKtF60dV7zG7DjSeDRCVWQygs:k4ZBVEbtTkNzmtF6p7ieFCVWYs
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Microsoft
Assembly Version: 3.0.0.1
InternalName: Adobe Reader.exe
FileVersion: 3.0.0.1
CompanyName:
LegalTrademarks:
Comments:
ProductName: Crypto
ProductVersion: 3.0.0.1
FileDescription: Crypto
OriginalFilename: Adobe Reader.exe

Ser.Ursu.22998 also known as:

K7AntiVirusTrojan ( 700000121 )
DrWebTrojan.ClipBankerNET.19
CynetMalicious (score: 99)
ALYacGen:Variant.Ser.Ursu.22998
CylanceUnsafe
ZillyaTrojan.CoinStealer.Win32.488
SangforTrojan.Win32.Save.a
AlibabaTrojan:MSIL/COINSTEAL.bd4bfb61
K7GWTrojan ( 700000121 )
Cybereasonmalicious.452510
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/PSW.CoinStealer.W
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderGen:Variant.Ser.Ursu.22998
NANO-AntivirusTrojan.Win32.Blocker.ebulvp
MicroWorld-eScanGen:Variant.Ser.Ursu.22998
TencentWin32.Trojan.Generic.Dypx
Ad-AwareGen:Variant.Ser.Ursu.22998
ComodoMalware@#n5igq226rloz
BitDefenderThetaGen:NN.ZemsilF.34686.am0@aeEqgon
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_COINSTEAL.SM2
McAfee-GW-EditionTrojan-FKOW!8265CDA45251
FireEyeGeneric.mg.8265cda4525102a1
EmsisoftGen:Variant.Ser.Ursu.22998 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.fwapu
AviraHEUR/AGEN.1114144
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataMSIL.Trojan.ClipBanker.C
McAfeeTrojan-FKOW!8265CDA45251
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
PandaTrj/CI.A
TrendMicro-HouseCallTSPY_COINSTEAL.SM2
RisingRansom.Generic!8.E315 (C64:YzY0OrUHKPOmCZx7)
YandexTrojan.PWS.CoinStealer!4VCzv5WI9hw
IkarusTrojan.MSIL.ClipBanker
FortinetMSIL/CoinStealer.W!tr.pws
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ser.Ursu.22998?

Ser.Ursu.22998 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment