Malware

Ursu.128130 removal tips

Malware Removal

The Ursu.128130 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.128130 virus can do?

    How to determine Ursu.128130?

    
    

    File Info:

    crc32: ED355C3B
    md5: 173734c946ab3d2799ecc5e374199e48
    name: 173734C946AB3D2799ECC5E374199E48.mlw
    sha1: c5851d9dacab327837e7728c53e39393926b7886
    sha256: 1a31f6482608c1098a08f7c969e7a3803648eff2e5ddd0aa9ccd9ea32526c4d6
    sha512: 6b4b6d40596ca301d12d32a5207403d411e4d6798011d1ac9a9f0a9f2868fd4219144b1b55b51ff30f011dad91c95aec4a9c492d1d347d6c15a200ef5357fc70
    ssdeep: 3072:52Cvw6UbTVRUu25RbD9RUttN19v0MiAPtYrxzmxoNRDuUlbR:tv5AnlcbDctL3v0MiAlY9zmxojDuUl
    type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

    Version Info:

    Translation: 0x0000 0x04b0
    LegalCopyright: x7f8ex5236x7f8eEx52361C56x7f8e6x7f8ex590dx590dx4e3d0x7f8ex4e3dx7f8ex5236x590dx7f8ex7f8eC5x4e3dx7f8e8x52361x590d0x5236x523656Ex590d1x590dx7f8ex5236x7f8e8x4e3dx4e3d1x590dx5236x590dx5236x590dx7f8e5x590d5x52365x4e3dx52365x590dx590d6x7f8ex7f8e0x590dx4e3dx5236x590dx590dx523630x5236x7f8ex7f8e5x590dx5236x4e3d5
    Assembly Version: 1.0.0.0
    InternalName: 77777.exe
    FileVersion: 1.0.0.0
    CompanyName: x7f8ex5236x7f8eEx52361C56x7f8e6x7f8ex590dx590dx4e3d0x7f8ex4e3dx7f8ex5236x590dx7f8ex7f8eC5x4e3dx7f8e8x52361x590d0x5236x523656Ex590d1x590dx7f8ex5236x7f8e8x4e3dx4e3d1x590dx5236x590dx5236x590dx7f8e5x590d5x52365x4e3dx52365x590dx590d6x7f8ex7f8e0x590dx4e3dx5236x590dx590dx523630x5236x7f8ex7f8e5x590dx5236x4e3d5
    LegalTrademarks: x7f8ex5236x7f8eEx52361C56x7f8e6x7f8ex590dx590dx4e3d0x7f8ex4e3dx7f8ex5236x590dx7f8ex7f8eC5x4e3dx7f8e8x52361x590d0x5236x523656Ex590d1x590dx7f8ex5236x7f8e8x4e3dx4e3d1x590dx5236x590dx5236x590dx7f8e5x590d5x52365x4e3dx52365x590dx590d6x7f8ex7f8e0x590dx4e3dx5236x590dx590dx523630x5236x7f8ex7f8e5x590dx5236x4e3d5
    Comments: x7f8ex5236x7f8eEx52361C56x7f8e6x7f8ex590dx590dx4e3d0x7f8ex4e3dx7f8ex5236x590dx7f8ex7f8eC5x4e3dx7f8e8x52361x590d0x5236x523656Ex590d1x590dx7f8ex5236x7f8e8x4e3dx4e3d1x590dx5236x590dx5236x590dx7f8e5x590d5x52365x4e3dx52365x590dx590d6x7f8ex7f8e0x590dx4e3dx5236x590dx590dx523630x5236x7f8ex7f8e5x590dx5236x4e3d5
    ProductName: x7f8ex5236x7f8eEx52361C56x7f8e6x7f8ex590dx590dx4e3d0x7f8ex4e3dx7f8ex5236x590dx7f8ex7f8eC5x4e3dx7f8e8x52361x590d0x5236x523656Ex590d1x590dx7f8ex5236x7f8e8x4e3dx4e3d1x590dx5236x590dx5236x590dx7f8e5x590d5x52365x4e3dx52365x590dx590d6x7f8ex7f8e0x590dx4e3dx5236x590dx590dx523630x5236x7f8ex7f8e5x590dx5236x4e3d5
    ProductVersion: 1.0.0.0
    FileDescription: x7f8ex5236x7f8eEx52361C56x7f8e6x7f8ex590dx590dx4e3d0x7f8ex4e3dx7f8ex5236x590dx7f8ex7f8eC5x4e3dx7f8e8x52361x590d0x5236x523656Ex590d1x590dx7f8ex5236x7f8e8x4e3dx4e3d1x590dx5236x590dx5236x590dx7f8e5x590d5x52365x4e3dx52365x590dx590d6x7f8ex7f8e0x590dx4e3dx5236x590dx590dx523630x5236x7f8ex7f8e5x590dx5236x4e3d5
    OriginalFilename: 77777.exe

    Ursu.128130 also known as:

    K7AntiVirusTrojan ( 0052a3d61 )
    LionicTrojan.MSIL.KillAV.lmjv
    Elasticmalicious (high confidence)
    DrWebBackDoor.Bladabindi.13678
    CynetMalicious (score: 99)
    ALYacGen:Variant.Ursu.128130
    CylanceUnsafe
    SangforSuspicious.Win32.Save.a
    CrowdStrikewin/malicious_confidence_100% (W)
    AlibabaBackdoor:MSIL/Bladabindi.ed518e7d
    K7GWTrojan ( 0052a3d61 )
    Cybereasonmalicious.946ab3
    SymantecML.Attribute.HighConfidence
    ESET-NOD32a variant of MSIL/Kryptik.NIZ
    APEXMalicious
    AvastWin32:Malware-gen
    KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
    BitDefenderGen:Variant.Ursu.128130
    NANO-AntivirusTrojan.Win32.Bladabindi.eytzmz
    MicroWorld-eScanGen:Variant.Ursu.128130
    TencentMsil.Backdoor.Bladabindi.Dwtj
    Ad-AwareGen:Variant.Ursu.128130
    SophosMal/Generic-R
    BitDefenderThetaGen:NN.ZemsilF.34236.om0@a0OKxPm
    VIPRETrojan.Win32.Generic!BT
    TrendMicroTROJ_GEN.R002C0PK121
    McAfee-GW-EditionGeneric.dqa
    FireEyeGeneric.mg.173734c946ab3d27
    EmsisoftGen:Variant.Ursu.128130 (B)
    SentinelOneStatic AI – Malicious PE
    JiangminBackdoor.MSIL.femw
    AviraHEUR/AGEN.1117491
    Antiy-AVLTrojan/Generic.ASMalwS.24EBD79
    MicrosoftBackdoor:MSIL/Bladabindi
    GDataGen:Variant.Ursu.128130
    AhnLab-V3Win-Trojan/MSILKrypt14.Exp
    McAfeeGeneric.dqa
    MAXmalware (ai score=96)
    VBA32Backdoor.Bladabindi
    PandaTrj/GdSda.A
    IkarusTrojan.MSIL.Bladabindi
    FortinetMSIL/Kryptik.NIZ!tr
    AVGWin32:Malware-gen
    Paloaltogeneric.ml

    How to remove Ursu.128130?

    Ursu.128130 removal tool
    • Download and install GridinSoft Anti-Malware.
    • Open GridinSoft Anti-Malware and perform a “Standard scan“.
    • Move to quarantine” all items.
    • Open “Tools” tab – Press “Reset Browser Settings“.
    • Select proper browser and options – Click “Reset”.
    • Restart your computer.

    About the author

    Paul Valéry

    I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

    Leave a Comment