Malware

Ursu.168505 removal guide

Malware Removal

The Ursu.168505 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.168505 virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.168505?


File Info:

crc32: 4EF5AD34
md5: 5ff217640f524b1c895ee99e92fb9534
name: 5FF217640F524B1C895EE99E92FB9534.mlw
sha1: ebb6d592aeb1b6ff2ced3cbd3d53a4f5f70f8c6f
sha256: 26673a0ed2be59eee71f6a08e433a4a65a35cc8d45d89971c1139a3bb3dcfbd7
sha512: 77b361f4565223e481c818c734220bdf9573140959eb7ec82cec7e369e633927d9b62adef1a4ec16f1540c3cdad2994e4d931359f5d7f73f34d4b6d807defc64
ssdeep: 3072:hV02c05w9ZW3bRiOqWxdrg/enod+KVErYnL:QEOW3AOTg/enC+KW0
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: WindowsApplication1.exe
FileVersion: 1.0.0.0
CompanyName: x7f8ex590dx5236x7f8ex5236
LegalTrademarks: x7f8ex590dx5236x7f8ex5236
Comments: x7f8ex590dx5236x7f8ex5236
ProductName: x7f8ex590dx5236x7f8ex5236
ProductVersion: 1.0.0.0
FileDescription: x7f8ex590dx5236x7f8ex5236
OriginalFilename: WindowsApplication1.exe

Ursu.168505 also known as:

K7AntiVirusTrojan ( 005152db1 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.DownLoader13.382
ALYacGen:Variant.Ursu.168505
ZillyaTrojan.Disfa.Win32.68008
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 005152db1 )
Cybereasonmalicious.40f524
SymantecBackdoor.Ratenjay
ESET-NOD32a variant of MSIL/Kryptik.GBA
APEXMalicious
AvastMSIL:GenMalicious-H [Trj]
ClamAVWin.Trojan.Bladbindi-1
KasperskyTrojan.MSIL.Disfa.ncgf
BitDefenderGen:Variant.Ursu.168505
NANO-AntivirusTrojan.Win32.Kryptik.facnay
MicroWorld-eScanGen:Variant.Ursu.168505
TencentMsil.Trojan.Disfa.Tcco
Ad-AwareGen:Variant.Ursu.168505
SophosMal/Generic-S
ComodoMalware@#6amz97vi01hp
BitDefenderThetaGen:NN.ZemsilF.34236.im0@aai00nn
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.5ff217640f524b1c
EmsisoftGen:Variant.Ursu.168505 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.MSIL.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2595DF7
MicrosoftBackdoor:MSIL/Bladabindi!rfn
GDataGen:Variant.Ursu.168505
AhnLab-V3Trojan/Win32.Tiggre.C2550019
McAfeeArtemis!5FF217640F52
MAXmalware (ai score=86)
PandaTrj/GdSda.A
IkarusTrojan.MSIL.Crypt
FortinetMSIL/Kryptik.GBA!tr
AVGMSIL:GenMalicious-H [Trj]
Paloaltogeneric.ml

How to remove Ursu.168505?

Ursu.168505 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment