Malware

About “Ser.Ursu.5896” infection

Malware Removal

The Ser.Ursu.5896 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Ursu.5896 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

gamemode.pk
random.pk
vputin.pk
rollscar.pk
getcars.pk

How to determine Ser.Ursu.5896?


File Info:

crc32: 9E3F0F0D
md5: 70907736014f76bb30bf0ce7e47a2eac
name: 70907736014F76BB30BF0CE7E47A2EAC.mlw
sha1: 37a4b01967de10e7e3238a037bc4b445c88e7418
sha256: 249c7909f04c0dc1b1d8d5f7f2dfd026fa1ca482d3de921e192b993ad01a3c03
sha512: 8b088e7427b71a43455d963dc9263b6ae9b6c4d7d32ca2575d89f1bf8ec52842e5f9515f1d7c3b9e3fab07d57ab93a607ee297e9facb7d09c27af505f68e6085
ssdeep: 192:HeHBvGvEgL8xfZFqZ+rdbZqODi4FchkGMzU8r:H+6EgIxfZprdbZqODi4FJt
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: ka4tsevgy2o
Assembly Version: 7.8.0.3
InternalName: paeofcesni3.exe
FileVersion: 7.8.0.3
CompanyName: rcmztfx4hjr
Comments: ynle1yheqdz
ProductName: gnpnndb1r00
ProductVersion: 7.8.0.3
FileDescription: gnpnndb1r00
OriginalFilename: paeofcesni3.exe

Ser.Ursu.5896 also known as:

K7AntiVirusTrojan-Downloader ( 0054b2571 )
LionicTrojan.MSIL.Azorult.i!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.25988
CynetMalicious (score: 100)
CAT-QuickHealTrojan.MsilFC.S8706209
ALYacGen:Variant.Ser.Ursu.5896
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojanPSW:MSIL/Azorult.5f7799dd
K7GWTrojan-Downloader ( 0054b2571 )
Cybereasonmalicious.6014f7
CyrenW32/Razy.DN.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.FKM
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Packed.Azorult-7570946-1
KasperskyHEUR:Trojan-PSW.MSIL.Azorult.gen
BitDefenderGen:Variant.Ser.Ursu.5896
NANO-AntivirusTrojan.Win32.Azorult.fuuyjs
MicroWorld-eScanGen:Variant.Ser.Ursu.5896
TencentMsil.Trojan-downloader.Agent.Agay
Ad-AwareGen:Variant.Ser.Ursu.5896
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34170.am0@au5KqEb
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.70907736014f76bb
EmsisoftGen:Variant.Ser.Ursu.5896 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1127849
eGambitUnsafe.AI_Score_97%
Antiy-AVLTrojan/Generic.ASMalwS.2B25B74
MicrosoftTrojan:MSIL/CryptInject!MTB
ArcabitTrojan.Ser.Ursu.D1708
ZoneAlarmHEUR:Trojan-PSW.MSIL.Azorult.gen
GDataGen:Variant.Ser.Ursu.5896
AhnLab-V3Malware/Win32.RL_Generic.C3626429
McAfeeArtemis!70907736014F
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Downloader.MSIL
PandaTrj/GdSda.A
YandexTrojan.DL.Agent!2QomAn9tmS4
IkarusTrojan-Downloader.MSIL.Agent
MaxSecureTrojan.Malware.73815250.susgen
FortinetW32/Agent.FKM!tr
AVGWin32:PWSX-gen [Trj]
Paloaltogeneric.ml

How to remove Ser.Ursu.5896?

Ser.Ursu.5896 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment