Malware

Ursu.180617 information

Malware Removal

The Ursu.180617 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.180617 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Attempts to create or modify system certificates

Related domains:

z.whorecord.xyz
a.tomx.xyz
pastebin.com

How to determine Ursu.180617?


File Info:

crc32: 2C770B23
md5: 305f71b53268b8aa0fb41f9506a5e721
name: 305F71B53268B8AA0FB41F9506A5E721.mlw
sha1: f2432958c6b31945997d365f35386c77500bf752
sha256: 207c1809616e2d9bfb9fd3706e73e436fd3581874df5fd384ab20f9b4bf88a0d
sha512: 7cce263919052381adeec8eef926a12f5bff157186d9efc63aaf6cd74d5d50afd6ab2508b8886f118c15537bd51813000a31c0427a3f203bc978dd2aabcb4f4e
ssdeep: 768:98Uhm2i5IiXe5GJM/vpbFj7iOSzbXxOPxaJPKTwKANElhk:9BK5bXRJKRbF/SzbXxsx0PKiNkhk
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: wert.exe
FileVersion: 1.0.0.0
ProductName: wert
ProductVersion: 1.0.0.0
FileDescription: wert
OriginalFilename: wert.exe

Ursu.180617 also known as:

K7AntiVirusTrojan-Downloader ( 0052d8c61 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader10.32701
CynetMalicious (score: 99)
ALYacGen:Variant.Ursu.180617
CylanceUnsafe
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan-Downloader ( 0052d8c61 )
Cybereasonmalicious.53268b
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Small.BOS
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.180617
NANO-AntivirusTrojan.Win32.Small.fapemd
MicroWorld-eScanGen:Variant.Ursu.180617
TencentWin32.Trojan.Generic.Lgtr
Ad-AwareGen:Variant.Ursu.180617
SophosMal/Generic-S
ComodoMalware@#h2pxq1cw5qdh
BitDefenderThetaAI:Packer.08DFF92325
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.305f71b53268b8aa
EmsisoftGen:Variant.Ursu.180617 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.ccebl
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.25E21A5
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataGen:Variant.Ursu.180617
AhnLab-V3Win-Trojan/MSILKrypt09.Exp
McAfeeArtemis!305F71B53268
MAXmalware (ai score=99)
PandaTrj/GdSda.A
IkarusTrojan.MSIL.Bladabindi
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.JXB!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ursu.180617?

Ursu.180617 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment