Malware

How to remove “Ursu.154255”?

Malware Removal

The Ursu.154255 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.154255 virus can do?

  • Injection (inter-process)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Japanese
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ursu.154255?


File Info:

crc32: 2CEF9904
md5: b532ea674fc65dcbb746c4b0493da18a
name: B532EA674FC65DCBB746C4B0493DA18A.mlw
sha1: 1f0a05124d4bb710440f5aeb1dde4d54f2fc420a
sha256: 161c6fba726743545176cba8b175044610cd619b185ebcad31d97adf56c1a7ef
sha512: 42a8d304f7d2f9ca107518d12d40275c8f62b4c4124a52985701ea7adacf95334cf0fb23ee093a88205e8d70efd9fedf058f108ed2a6166cf33e1c47e436fe1d
ssdeep: 3072:U99Z5UKj1xaTHHJhycmP66cz8zZcxveT+PZhhIrbxKYBS8efz:U99n1qHpOCsZcQ6hhhFN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2016
InternalName: PELoader.exe
FileVersion: 1.0.0.0
CompanyName: x7834x89e3x8865x4e01
ProductName: Mai Crack
ProductVersion: 1.0.0.0
FileDescription: Mai Crack
OriginalFilename: PELoader.exe
Translation: 0x0411 0x04b0

Ursu.154255 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusUnwanted-Program ( 004d38111 )
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.154255
CylanceUnsafe
K7GWUnwanted-Program ( 004d38111 )
Cybereasonmalicious.74fc65
SymantecTrojan.Gen.2
ESET-NOD32Win32/DllInject.FH potentially unsafe
APEXMalicious
AvastFileRepMalware
BitDefenderGen:Variant.Ursu.154255
NANO-AntivirusTrojan.Win32.MlwGen.ehcldm
MicroWorld-eScanGen:Variant.Ursu.154255
Ad-AwareGen:Variant.Ursu.154255
BitDefenderThetaGen:NN.ZexaF.34670.Au0@aOBiaKhH
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R06CC0PKI20
McAfee-GW-EditionPUP-XBQ-KM
FireEyeGen:Variant.Ursu.154255
EmsisoftGen:Variant.Ursu.154255 (B)
SentinelOneStatic AI – Suspicious PE
JiangminRiskTool.Gamehack.bsc
WebrootPUA.Gen
eGambitUnsafe.AI_Score_100%
MicrosoftTrojan:Win32/Ymacco.AB16
ArcabitTrojan.Ursu.D25A8F
GDataGen:Variant.Ursu.154255
McAfeePUP-XBQ-KM
MAXmalware (ai score=100)
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R06CC0PKI20
RisingTrojan.Occamy!8.F1CD (RDMK:cmRtazryVG1mu9TZyu4iv1f5Sa8X)
YandexTrojan.GenAsa!ez+OeyDV+uM
FortinetRiskware/DllInject
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Ursu.154255?

Ursu.154255 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment