Malware

What is “Ursu.193453”?

Malware Removal

The Ursu.193453 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.193453 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs

How to determine Ursu.193453?


File Info:

crc32: 6A7BF925
md5: 623683dccd5b7f0940939c4d1151106d
name: 623683DCCD5B7F0940939C4D1151106D.mlw
sha1: f594d2039dfcd75a2bbb6588656127ee69ecfabc
sha256: 15bb88ed41d7d6a430e02dc2255f0d195a6a445a5880d52ed2a46e8f3e0ac24f
sha512: c13ab44f440e0ae935bef9339bf98174581b4b79dc9a5b45f37696b717b2ec6d25823217b5b24d28c435524dc917291ec3b4a5282ec87ea54cb8916b9360e85d
ssdeep: 12288:QOoi4vfmY+bTa9/49fT7lT9s244ujyLdc8:Loi4XebxTRu4ujyLdc8
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: googlescholar.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: googlescholar
ProductVersion: 1.0.0.0
FileDescription: googlescholar
OriginalFilename: googlescholar.exe

Ursu.193453 also known as:

K7AntiVirusTrojan ( 004f41281 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.13735
MicroWorld-eScanGen:Variant.Ursu.193453
ALYacGen:Variant.Ursu.193453
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004f41281 )
Cybereasonmalicious.ccd5b7
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.CHS
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
BitDefenderGen:Variant.Ursu.193453
NANO-AntivirusTrojan.Win32.Stealer.fazwrp
TencentWin32.Trojan.Ursu.Wlpe
Ad-AwareGen:Variant.Ursu.193453
SophosMal/Generic-S
ComodoMalware@#3skbibm100c20
BitDefenderThetaGen:NN.ZemsilF.34170.Lm0@aS@eu8n
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Fareit.jm
FireEyeGeneric.mg.623683dccd5b7f09
EmsisoftGen:Variant.Ursu.193453 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1137839
Antiy-AVLTrojan/Generic.ASMalwS.2602C75
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Ursu.193453
McAfeeArtemis!623683DCCD5B
MAXmalware (ai score=95)
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R022H0CIR21
YandexTrojan.Kryptik!nd6nPz5eag0
IkarusTrojan.MSIL.Crypt
FortinetMSIL/Kryptik.FIF!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ursu.193453?

Ursu.193453 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment