Malware

Ursu.158478 information

Malware Removal

The Ursu.158478 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.158478 virus can do?

  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Generates some ICMP traffic

Related domains:

fouratlinks.com
boomboomrequest.com

How to determine Ursu.158478?


File Info:

crc32: 8571A343
md5: 2c175c596f60fca676e7c8e1a9c1e638
name: 2C175C596F60FCA676E7C8E1A9C1E638.mlw
sha1: d0f95cb7f22b781ca25554fdbe35b3ce1b4bf189
sha256: 3bc2a2aaf899ed766179252cf084f7bd40f1944c8a608d21527e9f6012cc5b8a
sha512: 53c1c650aa03004e4f6ad797fc0e2993023ff7fbdf2d82e5c9f71f7062a80f00d015595729ac1c551a4c7d5c99ef6a3f09f170f379af664a9cfe707111582fdc
ssdeep: 3072:nJPmU/QjrGcm6Tdhlk+T8f2WhPbPdQ9l9Di9Szl16cZ4QF:d4+cm6TdTkw8f2WhPklpiSv6+1
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2021
Assembly Version: 0.0.0.0
InternalName: Handler.exe
FileVersion: 0.0.0.0
CompanyName: cd_disc_install_setup_software
LegalTrademarks:
Comments: cd_disc_install_setup_software
ProductName: cd_disc_install_setup_software
ProductVersion: 0.0.0.0
FileDescription: cd_disc_install_setup_software
OriginalFilename: Handler.exe

Ursu.158478 also known as:

K7AntiVirusTrojan-Downloader ( 00588d741 )
LionicTrojan.MSIL.BaseLoader.a!c
DrWebAdware.WizzMonetize.1
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.158478
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojanDownloader:MSIL/BaseLoader.3807555c
K7GWTrojan-Downloader ( 00588d741 )
Cybereasonmalicious.96f60f
ESET-NOD32a variant of MSIL/Adware.CsdiMonetize.BG
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan-Downloader.MSIL.BaseLoader.gen
BitDefenderGen:Variant.Ursu.158478
MicroWorld-eScanGen:Variant.Ursu.158478
TencentMsil.Trojan-downloader.Baseloader.Hqvn
Ad-AwareGen:Variant.Ursu.158478
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34294.im0@aafmETh
McAfee-GW-EditionBehavesLike.Win32.PUP.cc
FireEyeGeneric.mg.2c175c596f60fca6
EmsisoftGen:Variant.Ursu.158478 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1146000
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Ursu.D26B0E
GDataWin32.Trojan-Downloader.Generic.NY20MS
AhnLab-V3Adware/Win.Generic.C4668709
McAfeeArtemis!2C175C596F60
MAXmalware (ai score=86)
MalwarebytesMachineLearning/Anomalous.96%
TrendMicro-HouseCallTROJ_GEN.R002H0CKJ21
FortinetAdware/CsdiMonetize
AVGWin32:MalwareX-gen [Trj]

How to remove Ursu.158478?

Ursu.158478 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment