Malware

How to remove “Ursu.122359”?

Malware Removal

The Ursu.122359 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.122359 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

api.telegram.org

How to determine Ursu.122359?


File Info:

crc32: AF6D3B5B
md5: 966247568a4bf57b90426c1efde3cef0
name: 966247568A4BF57B90426C1EFDE3CEF0.mlw
sha1: 3c1944347b8c83cd54807ca0cf09e302c6cdee3c
sha256: 249ee839ec0e08fe52f9b1c17461c0d7e5929f6ba4123308a33ba28b16198829
sha512: 1f2d1e63ecdefc8915bc3546d05b258e75226e3284c8f174e465a5c3334d3f685931aa7dabdc9658c9da62e7c45266f0d193cd2bca1297af1d0f755cccd7ca44
ssdeep: 768:MUnOPLzO12rsnmQCYgUtDfdpQ8o/4rz99K99rTOGfGmdZZiaKccapUPMnY:MGO+1AAmQP5T99K99rTOGfGmZZianOU
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2017
Assembly Version: 1.0.0.0
InternalName: Zlocker.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Zlocker
ProductVersion: 1.0.0.0
FileDescription: Zlocker
OriginalFilename: Zlocker.exe

Ursu.122359 also known as:

K7AntiVirusTrojan ( 005201691 )
LionicHacktool.Win32.Generic.3!c
DrWebTrojan.DownLoader26.22417
McAfeeRDN/Generic Downloader.x
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.8537
AlibabaRiskWare:Win32/Filecoder.aa2afb3a
K7GWTrojan ( 005201691 )
Cybereasonmalicious.68a4bf
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Filecoder.KY
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyHEUR:Hoax.Win32.Generic
BitDefenderGen:Variant.Ursu.122359
NANO-AntivirusRiskware.Win32.Ransom.eyphak
MicroWorld-eScanGen:Variant.Ursu.122359
TencentWin32.Trojan-psw.Generic.Htbu
Ad-AwareGen:Variant.Ursu.122359
SophosMal/Generic-R + Mal/ZLock-A
ComodoMalware@#2s6m5ajh08wmu
BitDefenderThetaGen:NN.ZemsilF.34266.dm0@am0sCl
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRDN/Generic Downloader.x
FireEyeGeneric.mg.966247568a4bf57b
EmsisoftGen:Variant.Ursu.122359 (B)
JiangminHoax.Generic.dz
AviraHEUR/AGEN.1101285
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.24BD12D
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataGen:Variant.Ursu.122359
VBA32Trojan.DownLoader
MAXmalware (ai score=95)
MalwarebytesRansom.Zlocker
PandaTrj/GdSda.A
YandexTrojan.Filecoder!SLsJQ+0kHwM
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Filecoder.KY!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ursu.122359?

Ursu.122359 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment