Malware

About “Ursu.145395” infection

Malware Removal

The Ursu.145395 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.145395 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ursu.145395?


File Info:

crc32: 4A96E1C2
md5: e56defe3884e0cab240edef4f9ae8237
name: E56DEFE3884E0CAB240EDEF4F9AE8237.mlw
sha1: 9cae1c528d4cc01777f205ef13abce48dad6fa27
sha256: d823be7dcf0a0a9b5dfe71e5450e0dcae985aa2e5db17d54688afe1a9b6b7fc0
sha512: b7c43dbb16970e0fac0ada34487fe167bb14c69124110a1d061775bf4aa6f6acd426fe6b13e5e15ebc257fee11f2c428c0ae4621a0b88b47ab5a15dd787e0090
ssdeep: 384:2KsVPtjWOBY5pUvlJ1stkjZ7hKWPAoWFZDxfhNQ/e13X2kt5rRbH9StwYGc5:2KgBY5pUv6qjZNnJyZDlMyj5JIt2c5
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: j.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: j.exe

Ursu.145395 also known as:

Elasticmalicious (high confidence)
DrWebBackDoor.BladabindiNET.9
MicroWorld-eScanGen:Variant.Ursu.145395
FireEyeGeneric.mg.e56defe3884e0cab
ALYacGen:Variant.Ursu.145395
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Variant.Ursu.145395
K7GWTrojan ( 700000121 )
Cybereasonmalicious.3884e0
BitDefenderThetaGen:NN.ZemsilF.34700.bm0@aSPIF2o
CyrenW32/Revetrat.A.gen!Eldorado
APEXMalicious
ClamAVWin.Trojan.Generic-6417450-0
KasperskyHEUR:Trojan-Spy.MSIL.Agent.gen
Ad-AwareGen:Variant.Ursu.145395
EmsisoftGen:Variant.Ursu.145395 (B)
F-SecureTrojan.TR/ATRAPS.Gen
ZillyaTrojan.Bladabindi.Win32.113025
TrendMicroBKDR_BLADABI.SMC
SophosML/PE-A
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan[Spy]/MSIL.Agent
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Ursu.D237F3
SUPERAntiSpywareTrojan.Agent/Gen-Injector
ZoneAlarmHEUR:Trojan-Spy.MSIL.Agent.gen
GDataGen:Variant.Ursu.145395
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Bladabindi.R273021
MAXmalware (ai score=80)
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.Agent.P
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Bladabindi.AS
TrendMicro-HouseCallBKDR_BLADABI.SMC
RisingBackdoor.Njrat!1.C5D1 (CLASSIC)
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Bladabindi.AS!tr
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM03.0.1811.Malware.Gen

How to remove Ursu.145395?

Ursu.145395 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment