Malware

Ursu.150471 (B) removal guide

Malware Removal

The Ursu.150471 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.150471 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ursu.150471 (B)?


File Info:

crc32: 71E64BD4
md5: 270abdf891b1b9d74a13a58fa66e6dce
name: restriktion.exe
sha1: a237c661720aa68889abc0dc5322c0d21a7e79a2
sha256: 0ff50881260e6c966b8ac7f4a10682d31002637be3ba8a7d22f5561078815969
sha512: 5c8a9e03b985c53503c1616be2046eb7411b3548c533b9745751394d21716056182e589df9494cc793c3f0c91aec574174994f0e8f442b3ec23604cea0ea7132
ssdeep: 768:7y8XCu6m/7wAO0iQfqNhlBdy65272KyQP1JY75uNy8X:Mud+hg6FW1jPo1u
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0410 0x04b0
LegalCopyright: konfektions
InternalName: restriktion
FileVersion: 1.00.0001
CompanyName: freedOM
LegalTrademarks: Scoret3
Comments: TRIEDNESS
ProductName: martinist
ProductVersion: 1.00.0001
FileDescription: Osteophagia
OriginalFilename: restriktion.exe

Ursu.150471 (B) also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Ursu.150471
FireEyeGen:Variant.Ursu.150471
McAfeeArtemis!270ABDF891B1
CylanceUnsafe
AegisLabTrojan.Win32.Ursu.4!c
SangforMalware
K7AntiVirusTrojan ( 00561de71 )
BitDefenderGen:Variant.Ursu.150471
K7GWTrojan ( 00561de71 )
Cybereasonmalicious.891b1b
TrendMicroTROJ_GEN.R015C0PC820
BitDefenderThetaGen:NN.ZevbaF.34098.gm0@ayTPAioG
F-ProtW32/Injector.ZV.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTrojan.Win32.WACATAC.THCAOBO
AvastWin32:Trojan-gen
GDataGen:Variant.Ursu.150471
KasperskyTrojan-Spy.Win32.Noon.avwv
AlibabaTrojanSpy:Win32/Injector.6a5bf5cf
NANO-AntivirusTrojan.Win32.Noon.helidl
RisingSpyware.Noon!8.E7C9 (CLOUD)
Ad-AwareGen:Variant.Ursu.150471
EmsisoftGen:Variant.Ursu.150471 (B)
F-SecureTrojan.TR/Injector.xiizn
DrWebTrojan.Siggen9.17966
McAfee-GW-EditionRDN/Generic.dx
Trapminemalicious.high.ml.score
SophosMal/Generic-S
APEXMalicious
CyrenW32/Injector.ZV.gen!Eldorado
JiangminTrojanSpy.Noon.oka
AviraTR/Injector.xiizn
Antiy-AVLTrojan/Win32.Wacatac
ArcabitTrojan.Ursu.D24BC7
ZoneAlarmTrojan-Spy.Win32.Noon.avwv
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
VBA32BScope.Backdoor.Remcos
ALYacSpyware.Noon.gen
MAXmalware (ai score=99)
MalwarebytesTrojan.MalPack.VB
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.EKWS
TencentWin32.Trojan-spy.Noon.Hooo
IkarusTrojan.VB.Crypt
eGambitUnsafe.AI_Score_100%
FortinetW32/EKWS!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.Spy.f6d

How to remove Ursu.150471 (B)?

Ursu.150471 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment