Malware

Ursu.148819 (file analysis)

Malware Removal

The Ursu.148819 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.148819 virus can do?

  • Anomalous binary characteristics

How to determine Ursu.148819?


File Info:

crc32: 743D4C9E
md5: 43180e340c7f732d6d32b5abcf4436cb
name: 43180E340C7F732D6D32B5ABCF4436CB.mlw
sha1: 0bb18d16ea83b681d5cba9da954a0687e45c82aa
sha256: 13c0a9ef026b134c65408706213b1d39baf2cc9dde2af35c67786f05d24eea64
sha512: 0cb2a7d9613874cf0d3b49f796ea3890a9ec5138c1deb4b121019e9ddadad9e7190ecbc7c1d6f83c509348c76a174eef31707a35cb6637c314625a2f18774213
ssdeep: 96:QqKHCozpGu7X1AYw06dY8IwoH6/EVTh9/C91RxYzNt:QqKHCo37lB2lvwT7cV6
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: Stealer.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: Stealer.exe

Ursu.148819 also known as:

K7AntiVirusTrojan ( 700000121 )
Elasticmalicious (high confidence)
DrWebTrojan.ClipBankerNET.7
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.148819
SangforTrojan.Win32.Save.a
K7GWTrojan ( 700000121 )
Cybereasonmalicious.40c7f7
CyrenW32/ClipBanker.M.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/ClipBanker.LT
APEXMalicious
AvastWin32:BankerX-gen [Trj]
ClamAVWin.Packed.Clipbanker-9792195-0
KasperskyHEUR:Trojan-Banker.MSIL.ClipBanker.gen
BitDefenderGen:Variant.Ursu.148819
SUPERAntiSpywareTrojan.Agent/Gen-Stealer
MicroWorld-eScanGen:Variant.Ursu.148819
Ad-AwareGen:Variant.Ursu.148819
BitDefenderThetaGen:NN.ZemsilF.34670.am0@aqK8bQh
TrendMicroTrojanSpy.MSIL.CLIPBANKER.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.xt
FireEyeGeneric.mg.43180e340c7f732d
EmsisoftGen:Variant.Ursu.148819 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_98%
MicrosoftTrojan:MSIL/ClipBanker.GG!MTB
ZoneAlarmHEUR:Trojan-Banker.MSIL.ClipBanker.gen
GDataMSIL.Trojan.ClipBanker.F
AhnLab-V3Malware/Win32.RL_Generic.C3552551
McAfeeArtemis!43180E340C7F
MAXmalware (ai score=83)
MalwarebytesTrojan.Agent.MSIL
TrendMicro-HouseCallTrojanSpy.MSIL.CLIPBANKER.SM
RisingSpyware.ClipBanker!1.D058 (CLASSIC)
IkarusTrojan.MSIL.ClipBanker
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/ClipBanker.LT!tr
AVGWin32:BankerX-gen [Trj]

How to remove Ursu.148819?

Ursu.148819 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment