Malware

Ursu.208788 removal

Malware Removal

The Ursu.208788 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.208788 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.208788?


File Info:

crc32: 27D0A598
md5: b8b5c4fd838dc1dea318e5fd802a258a
name: B8B5C4FD838DC1DEA318E5FD802A258A.mlw
sha1: 67a352c0bcc11f4bcca3ec0c83b6f9b1f26767ba
sha256: 4d7a89a6c16c3f3e24e96a58c19a4246d98c78b6f2a7a424055ed6d418ee48cc
sha512: 91a676f7bee50c53c2621dc3411c137ae75eef16e0572be3741742c095b4bd6c21fdc1159428c01d833d55ea69d81973a3d966de726e71f8a72cdf0b995f71cd
ssdeep: 24576:G8xhG71YBPzKmi/vvn9cRlVuxj4lDTrx5ij/FFxbiy:VhFPk/vvnWsmTrxIrF
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1997-2017 Simon Tatham.
InternalName: PuTTY
FileVersion: Release 0.69
CompanyName: Simon Tatham
ProductName: PuTTY suite
ProductVersion: Release 0.69
FileDescription: SSH, Telnet and Rlogin client
OriginalFilename: PuTTY
Translation: 0x0809 0x04b0

Ursu.208788 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.208788
FireEyeGeneric.mg.b8b5c4fd838dc1de
ALYacGen:Variant.Ursu.208788
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderGen:Variant.Ursu.208788
K7GWTrojan ( 005132361 )
K7AntiVirusTrojan ( 005132361 )
BitDefenderThetaGen:NN.ZemsilF.34590.2m2@a8tdghbi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.SQR
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.MSIL.Generic
NANO-AntivirusTrojan.Win32.Stealer.ewyzpg
AegisLabTrojan.MSIL.Generic.4!c
RisingTrojan.Injector!8.C4 (CLOUD)
Ad-AwareGen:Variant.Ursu.208788
F-SecureHeuristic.HEUR/AGEN.1114859
DrWebTrojan.PWS.Stealer.13025
TrendMicroBKDR_NANOCORE.SMA
McAfee-GW-EditionTrojan-FNRV!B8B5C4FD838D
EmsisoftGen:Variant.Ursu.208788 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1114859
MAXmalware (ai score=98)
Antiy-AVLTrojan/MSIL.AGeneric
MicrosoftBackdoor:MSIL/Bladabindi
ArcabitTrojan.Ursu.D32F94
AhnLab-V3Trojan/Win32.RL_Generic.C4276614
ZoneAlarmHEUR:Trojan.MSIL.Generic
GDataGen:Variant.Ursu.208788
CynetMalicious (score: 85)
McAfeeTrojan-FNRV!B8B5C4FD838D
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_NANOCORE.SMA
TencentMsil.Trojan.Generic.Phqb
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Generic.AP.11BB56!tr
AVGWin32:Malware-gen
Qihoo-360Win32/Trojan.7c5

How to remove Ursu.208788?

Ursu.208788 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment