Malware

Should I remove “Ursu.189797”?

Malware Removal

The Ursu.189797 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.189797 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

runtime.kro.kr

How to determine Ursu.189797?


File Info:

crc32: 41CCAD8A
md5: 39c29cb3d7eff85351edb2f2fdd783c8
name: 39C29CB3D7EFF85351EDB2F2FDD783C8.mlw
sha1: 3412e183dc0cdc851ac2fb62cb4edd6ca25cf8d2
sha256: 4801a8db03ce384f23258947d5e8f1ace5d58a3274920d67f04b3429ba19173c
sha512: a7b24b849498378fffecb4f433321e4e4d76de92091ef4ee7f83a129f0821b7cb6fc5b4dcf7462eb3b829dc99769c58005f026b7c42261100385fe15efa53aae
ssdeep: 1536:Dtxktg7pjqu91IiAZ+FoJpOJR8nSL5NjclrXaa7N0XhB121MKjwh:huUguzwpOJR6Sl/u0XgMKj+
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Ursu.189797 also known as:

K7AntiVirusTrojan ( 700000121 )
Elasticmalicious (high confidence)
DrWebBackDoor.BladabindiNET.27
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.189797
CylanceUnsafe
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 700000121 )
Cybereasonmalicious.3d7eff
BaiduMSIL.Backdoor.Bladabindi.a
CyrenW32/MSIL_Bladabindi.DG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Bladabindi.AS
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Dropper.njRAT-7436651-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.189797
ViRobotBackdoor.Win32.Bladabindi.Gen.A
MicroWorld-eScanGen:Variant.Ursu.189797
Ad-AwareGen:Variant.Ursu.189797
SophosML/PE-A + Troj/Bbindi-W
BitDefenderThetaGen:NN.ZemsilF.34236.fqX@aihNG1f
McAfee-GW-EditionBehavesLike.Win32.Generic.mm
FireEyeGeneric.mg.39c29cb3d7eff853
EmsisoftGen:Variant.Ursu.189797 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.28AF990
MicrosoftBackdoor:MSIL/Bladabindi.AP
ArcabitTrojan.Ursu.D2E565
GDataGen:Variant.Ursu.189797
AhnLab-V3Trojan/Win32.Llac.C63023
Acronissuspicious
McAfeeBackDoor-FDNN!39C29CB3D7EF
MAXmalware (ai score=83)
VBA32Backdoor.MSIL.Bladabindi
PandaTrj/GdSda.A
RisingBackdoor.Njrat!1.9E49 (CLASSIC)
YandexTrojan.Agent!LZWm+Cj1JvA
IkarusTrojan.MSIL.Bladabindi
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Bladabindi.AS!tr
AVGWin32:Trojan-gen

How to remove Ursu.189797?

Ursu.189797 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment