Malware

Ursu.193170 (file analysis)

Malware Removal

The Ursu.193170 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.193170 virus can do?

  • Network activity detected but not expressed in API logs

How to determine Ursu.193170?


File Info:

crc32: 8E8C5FB5
md5: e47ff9df1cb2e259d1e7d9916ee5a213
name: E47FF9DF1CB2E259D1E7D9916EE5A213.mlw
sha1: 2fb969e6fd76b995ecbc01684bbb1150d10e7e03
sha256: 4f4f7e310243f443c19dc297f2d14f1a37dc495035e6ed1cb00689eac22ceb8a
sha512: e677360d34420ce288c6a97ec54f6a74a059c986ff3ed342afcbd5847933a954d64a0559b5c7a3390a9456424b5004462d8591c9b6ea801aa5d457fdf761c314
ssdeep: 1536:Rj5PlBKbJXC54cj/xalAvxysl36oBprefLG7HfLRzVtsuBAFiV3kYrNy:h5tBiC54cjcCvxrxYLS/zkYk
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2015
Assembly Version: 1.0.0.0
InternalName: W.exe
FileVersion: 1.0.0.0
ProductName: W
ProductVersion: 1.0.0.0
FileDescription: W
OriginalFilename: W.exe

Ursu.193170 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.193170
FireEyeGeneric.mg.e47ff9df1cb2e259
McAfeeArtemis!E47FF9DF1CB2
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.Kryptik.Win32.819789
AegisLabTrojan.Win32.Blocker.j!c
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Ursu.193170
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.f1cb2e
BitDefenderThetaGen:NN.ZemsilF.34590.gq0@aa@I8jo
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.CDC
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Backdoor.MSIL.Generic
AlibabaBackdoor:MSIL/Generic.2b8f6e75
NANO-AntivirusTrojan.Win32.Agent.dyzfyh
RisingRansom.Blocker!8.12A (CLOUD)
Ad-AwareGen:Variant.Ursu.193170
SophosMal/Generic-S
ComodoMalware@#1szpgyjusx4e4
F-SecureHeuristic.HEUR/AGEN.1108908
DrWebTrojan.MulDropNET.27
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.ct
EmsisoftGen:Variant.Ursu.193170 (B)
IkarusTrojan-Dropper.Win32.Sysn
JiangminTrojan.Blocker.adm
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1108908
MAXmalware (ai score=89)
Antiy-AVLTrojan[Ransom]/Win32.Blocker
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:MSIL/Bladabindi.B
ArcabitTrojan.Ursu.D2F292
AhnLab-V3Malware/Win32.RL_Generic.C4219958
ZoneAlarmHEUR:Backdoor.MSIL.Generic
GDataGen:Variant.Ursu.193170
CynetMalicious (score: 85)
VBA32TScope.Trojan.MSIL
ALYacGen:Variant.Ursu.193170
PandaTrj/GdSda.A
TencentWin32.Trojan.Blocker.Ajln
YandexTrojan.Blocker!R4U6C287Ud8
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Agent.CAZ!tr
WebrootW32.Trojan.GenKD
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Backdoor.Generic.HgIASOsA

How to remove Ursu.193170?

Ursu.193170 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment