Malware

What is “Ursu.151924”?

Malware Removal

The Ursu.151924 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.151924 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Anomalous binary characteristics

How to determine Ursu.151924?


File Info:

crc32: D1389770
md5: 1ec880827808507cd9a5b330fa2212b4
name: 1EC880827808507CD9A5B330FA2212B4.mlw
sha1: 05100c49db956d5e09cb842a508597b8e0329c45
sha256: d98af4b247010bdf3d9f278f8e147206094785b132b31e2c716f146ac38504c7
sha512: 4827f746e61477e6f88b82a15cda1cb5f8077dccc9b41020600d0046e76592530c16d15e9235590f61ad3c50484db0662372cf02ddc03d3e37c5390db7780c59
ssdeep: 24576:76NFZqejY8NFZqe5K8aCBJ8d6sxxdV8Cyv:ePZqeU8PZqep8z
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright CC xa92018 .
Assembly Version: 1.5.1.3
InternalName: mygamexys.exe
FileVersion: 1.5.1.3
CompanyName: krapshmidt ltd
LegalTrademarks: krapshmidt
Comments: krapshmidt
ProductName: krapshmidt Client
ProductVersion: 1.5.1.3
FileDescription: krapshmidt
OriginalFilename: mygamexys.exe

Ursu.151924 also known as:

K7AntiVirusAdware ( 005465501 )
LionicRiskware.Win32.CloudGuard.1!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen7.43253
CynetMalicious (score: 99)
ALYacGen:Variant.Ursu.151924
CylanceUnsafe
ZillyaAdware.CloudGuard.Win32.1126
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:MSIL/CloudGuard.8c1908dd
K7GWAdware ( 005465501 )
Cybereasonmalicious.278085
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Adware.CloudGuard.D
APEXMalicious
AvastWin32:AdwareX-gen [Adw]
BitDefenderGen:Variant.Ursu.151924
NANO-AntivirusTrojan.Win32.CloudGuard.ezpkqs
MicroWorld-eScanGen:Variant.Ursu.151924
TencentMsil.Adware.Cloudguard.Ecuy
Ad-AwareGen:Variant.Ursu.151924
SophosCloudGuard (PUA)
BitDefenderThetaGen:NN.ZemsilF.34170.un0@a8pCDop
VIPREMSIL.Adware.CloudGuard
McAfee-GW-EditionBehavesLike.Win32.Generic.th
FireEyeGeneric.mg.1ec880827808507c
EmsisoftGen:Variant.Ursu.151924 (B)
SentinelOneStatic AI – Malicious PE
AviraADWARE/CloudGuard.Gen
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataGen:Variant.Ursu.151924
AhnLab-V3PUP/Win32.CloudGuard.R222514
McAfeePUP-XEQ-QX
MAXmalware (ai score=96)
VBA32TScope.Trojan.MSIL
MalwarebytesGeneric.Trojan.Malicious.DDS
TrendMicro-HouseCallTROJ_GEN.R002C0PIT21
YandexPUA.CloudGuard!0vq5qsrYrkU
IkarusAdWare.MSIL.Cloudguard
FortinetMSIL/CloudGuard.D
AVGWin32:AdwareX-gen [Adw]
Paloaltogeneric.ml

How to remove Ursu.151924?

Ursu.151924 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment