Malware

Ursu.182869 removal instruction

Malware Removal

The Ursu.182869 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.182869 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
redeworf71.duckdns.org

How to determine Ursu.182869?


File Info:

crc32: 83FF3D22
md5: eca378a628b069be3a3f58078648db4e
name: ECA378A628B069BE3A3F58078648DB4E.mlw
sha1: a4dcb71990fba908a26b5ded3bdeb458bf2d6fc8
sha256: 33b6280b8e6ab606c8f6524dcb5fb43c575e28f0bba651a2a415a5c439652df1
sha512: 3c5e06a85345396ed9ea49440c75948d3fa2b7022ec1f59919ef95f01c7587517e3a143f0614452b50eea0f8ec1693b2a1e9e2ecd54e1ce1bcd632f4bdf4467c
ssdeep: 1536:7DLv2Ap55tYeRvg105LLqtrR4RNBJgWWbjh4NaGgjWOQuxkOtDS5qxYp+SF+3Es:7DLH2O0yLxRxgXvCg6JZVQHrAUf8
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Rede Markerxa9 2018
Assembly Version: 2.1.3.0
InternalName: Rede Marker Leite de Toddy.exe
FileVersion: 2.1.3.1
CompanyName: Rede Marker
LegalTrademarks: Rede Marker
Comments: Rede Marker
ProductName: Rede Marker
ProductVersion: 2.1.3.1
FileDescription: Processo de Host para Servixe7os do Windows
OriginalFilename: Rede Marker Leite de Toddy.exe

Ursu.182869 also known as:

K7AntiVirusTrojan ( 0052cb231 )
LionicTrojan.MSIL.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.182869
ALYacGen:Variant.Ursu.182869
CylanceUnsafe
BitDefenderGen:Variant.Ursu.182869
K7GWTrojan ( 0052cb231 )
Cybereasonmalicious.628b06
BitDefenderThetaGen:NN.ZemsilF.34110.jm0@aeFtUPp
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.NMM
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.MSIL.Generic
NANO-AntivirusTrojan.Win32.Kryptik.feujib
TencentMsil.Trojan.Generic.Anpj
Ad-AwareGen:Variant.Ursu.182869
SophosMal/Generic-S
ComodoMalware@#sucbybslv5fh
DrWebTrojan.PackedNET.122
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.eca378a628b069be
EmsisoftGen:Variant.Ursu.182869 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1106626
eGambitUnsafe.AI_Score_92%
Antiy-AVLTrojan/Generic.ASMalwS.26C75AD
GDataGen:Variant.Ursu.182869
MAXmalware (ai score=96)
IkarusTrojan.MSIL.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.NMM!tr
PandaTrj/GdSda.A

How to remove Ursu.182869?

Ursu.182869 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment