Malware

Ursu.155583 removal instruction

Malware Removal

The Ursu.155583 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.155583 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.155583?


File Info:

crc32: FD1A724C
md5: 73d26bc654e12e624a3fdd9c400ceea7
name: 73D26BC654E12E624A3FDD9C400CEEA7.mlw
sha1: 71e6340b4f11830192a26b2b7f464af0dcecf0b9
sha256: 1a1fcfbb96d4cbb327f267e384630dbb1e8a1ff70de09dccfb5dd91e6daa55ec
sha512: 66ad6b69051af20270a45c2fd9d9e58bbcb909e11c4eceb0fa2c8cdc96ce6ff0c9686fa74f0cd24d19a25943dcfadee1db3932cc00cdb68cca463b3b2d514564
ssdeep: 12288:GyZulWiAJ8Q0w2qpnsYnJdopgah8l8rtcmzuQamCT:Gy8Wjecnp8rMn
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: ACTIONCENTER
FileVersion: 10.0.16299.15 (WinBuild.160101.0800)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 10.0.16299.15
FileDescription: Security and Maintenance
OriginalFilename: ACTIONCENTER.DLL
Translation: 0x0409 0x04b0

Ursu.155583 also known as:

K7AntiVirusTrojan ( 005275501 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.155583
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/CoinMiner.ali1002002
K7GWTrojan ( 005275501 )
Cybereasonmalicious.654e12
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/CoinMiner.AKM
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.155583
NANO-AntivirusTrojan.Win32.CoinMiner.eziuig
MicroWorld-eScanGen:Variant.Ursu.155583
TencentWin32.Trojan.Generic.Airy
Ad-AwareGen:Variant.Ursu.155583
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34236.Lq0@aOlkvqci
McAfee-GW-EditionBehavesLike.Win32.Suspect.jc
FireEyeGeneric.mg.73d26bc654e12e62
EmsisoftGen:Variant.Ursu.155583 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1126172
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.252FCC0
MicrosoftTrojan:Win32/Occamy.C1A
ArcabitTrojan.Ursu.D25FBF
GDataGen:Variant.Ursu.155583
McAfeeArtemis!73D26BC654E1
VBA32Trojan.Fuerboos
MalwarebytesRiskWare.BitCoinMiner
PandaTrj/Genetic.gen
IkarusTrojan.MSIL.CoinMiner
FortinetMSIL/CoinMiner.AKM!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ursu.155583?

Ursu.155583 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment