Malware

Ursu.125369 removal tips

Malware Removal

The Ursu.125369 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.125369 virus can do?

  • Unconventionial language used in binary resources: Vietnamese
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Ursu.125369?


File Info:

name: C34646F3BF6E556C16F6.mlw
path: /opt/CAPEv2/storage/binaries/c297dd19734952e821e39dcdbb681a295d5be6db0d7497983beef54565e1adff
crc32: 47912CA9
md5: c34646f3bf6e556c16f6d0b979ee236f
sha1: dad183760f9b8c4286cb77a3845ec6dca8744ffd
sha256: c297dd19734952e821e39dcdbb681a295d5be6db0d7497983beef54565e1adff
sha512: 2b380534969bfaa9f15e7f76d9bd416a2a7f869c183858b2397b222c5815619a76d6d7d7412a63e6b5afcf7d91d6516f152cc72bfe9fdd8e5f75dae5c4db2b34
ssdeep: 6144:sbB4hdVVRg7kUaeVqMh87yIhZ1GP56bVa+2ibjA/82/Cu1h/:suhVRg7kUnVq37yIhZ1GPgpa1i3A/lCq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17B741288E54EE221F2A80BF2A866ED3F1C786FF718A528DDED811D3B4F51E540874674
sha3_384: 701b14c9620ba7cb2f576200f93be898f4cc82bed0f574685e1db2fa1a15f1c06f0d723e1b9aba7b1c3dad1c64c50806
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-07-28 09:42:33

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: SQL Writter JSS
FileVersion: 1.0.0.0
InternalName: stub2.exe
LegalCopyright: Copyright © 2018
LegalTrademarks:
OriginalFilename: stub2.exe
ProductName: SQL Writter JSS
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Ursu.125369 also known as:

BkavW32.AIDetectMalware.CS
AVGWin32:Malware-gen
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.125369
FireEyeGeneric.mg.c34646f3bf6e556c
SkyhighBehavesLike.Win32.Trojan.fc
McAfeeArtemis!C34646F3BF6E
MalwarebytesMachineLearning/Anomalous.100%
VIPREGen:Variant.Ursu.125369
SangforTrojan.MSIL.Agent.gen
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanSpy:MSIL/GenKryptik.af452e89
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_90% (D)
VirITTrojan.Win32.Dnldr22.BHJG
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/GenKryptik.CGQE
APEXMalicious
KasperskyHEUR:Trojan-Spy.MSIL.Agent.gen
BitDefenderGen:Variant.Ursu.125369
NANO-AntivirusTrojan.Win32.GenKryptik.figxrj
AvastWin32:Malware-gen
TencentMsil.Trojan-Spy.Agent.Wylw
EmsisoftGen:Variant.Ursu.125369 (B)
F-SecureTrojan.TR/Spy.Agent.uumsf
DrWebTrojan.DownLoader22.22548
ZillyaTrojan.Agent.Win32.918015
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.MSIL.xxh
AviraTR/Spy.Agent.uumsf
MAXmalware (ai score=100)
Antiy-AVLTrojan[Spy]/MSIL.Agent
MicrosoftBackdoor:Win32/Xiclog.A
XcitiumMalware@#3lb3yb60fqxpd
ArcabitTrojan.Ursu.D1E9B9
ZoneAlarmHEUR:Trojan-Spy.MSIL.Agent.gen
GDataGen:Variant.Ursu.125369
GoogleDetected
AhnLab-V3Backdoor/Win32.Xiclog.C2676548
BitDefenderThetaGen:NN.ZemsilF.36802.wm0@aW@Qt1eG
ALYacGen:Variant.Ursu.125369
Cylanceunsafe
PandaTrj/CI.A
RisingBackdoor.Xiclog!8.E79B (CLOUD)
YandexTrojan.GenKryptik!+sia9E9s6ds
IkarusTrojan.MSIL.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent!tr
DeepInstinctMALICIOUS

How to remove Ursu.125369?

Ursu.125369 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment