Malware

How to remove “Ursu.175325”?

Malware Removal

The Ursu.175325 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.175325 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • A process was set to shut the system down when terminated
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

wnshoting13.ddns.net

How to determine Ursu.175325?


File Info:

crc32: A4A739DF
md5: a905f4dc3a7b7e08a15abb8f5b9d4b49
name: A905F4DC3A7B7E08A15ABB8F5B9D4B49.mlw
sha1: c1d7f9fc741848f55b42058bc433fe7166204d9d
sha256: dd6bc4a0f50eb40a378754464bb46bfa9acc8ec89e934d4143cd1bbfd65be7a7
sha512: ad21b62eaffb7e466d3ad45fefc3277f008866898ed4aaac8c5b604269e09961aa15e46826343aa38201d9bd9cd1d88960a16deb918b4ae4d1e07434b42a0fcb
ssdeep: 3072:WrJFVYLCDR/uIWntXTrEXyuHGUVgzkcROnjU:WrSCtGn9TNlkckjU
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Ursu.175325 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.175325
FireEyeGeneric.mg.a905f4dc3a7b7e08
McAfeeBackDoor-FDNN!A905F4DC3A7B
CylanceUnsafe
ZillyaTrojan.Bladabindi.Win32.84116
SangforMalware
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Variant.Ursu.175325
K7GWTrojan ( 700000121 )
Cybereasonmalicious.c3a7b7
BaiduMSIL.Backdoor.Bladabindi.a
CyrenW32/MSIL_Bladabindi.P.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Packed.Bladabindi-6917466-0
KasperskyHEUR:Backdoor.MSIL.Generic
NANO-AntivirusTrojan.Win32.Bladabindi.ekmfky
RisingBackdoor.Njrat!1.9E49 (CLASSIC)
Ad-AwareGen:Variant.Ursu.175325
SophosMal/Generic-R + Troj/Bbindi-W
ComodoMalware@#8m8m9ohg9cx9
F-SecureTrojan.TR/ATRAPS.Gen2
DrWebTrojan.DownLoader23.45039
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
EmsisoftGen:Variant.Ursu.175325 (B)
IkarusTrojan.MSIL.Injector
AviraTR/ATRAPS.Gen2
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:MSIL/Bladabindi.AJ
ArcabitTrojan.Ursu.D2ACDD
ZoneAlarmHEUR:Backdoor.MSIL.Generic
GDataGen:Variant.Ursu.175325
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Llac.C63023
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.34804.gqW@a0pMfXf
ALYacGen:Variant.Ursu.175325
MalwarebytesBackdoor.Bladabindi
PandaTrj/Genetic.gen
ESET-NOD32a variant of MSIL/Agent.BQC
TencentWin32.Trojan.Generic.Lkwz
YandexTrojan.Agent!vJDqbZtVoeU
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Generic.AP.586B0!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Ursu.175325?

Ursu.175325 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment