Malware

Ursu.212383 information

Malware Removal

The Ursu.212383 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.212383 virus can do?

  • Starts servers listening on 0.0.0.0:12345
  • Anomalous binary characteristics

How to determine Ursu.212383?


File Info:

crc32: 5B5DD451
md5: 5a5da20f88f74849a8ce4d3ff3d631bf
name: 5A5DA20F88F74849A8CE4D3FF3D631BF.mlw
sha1: 8902da7d1525dea0309800bce9578e27409bece2
sha256: 80512870994179120ae89cb7f81b03e11fcb571d30a1562dacb8d97641635453
sha512: c748cb0bbd0f06dac0b08ed989f0ecb096f6e342119eb7abeb9d7288fdff1a42cd83b2907493397c147f2af7e4e1ca5fbd30aa28b6b86f36a21d923dfac91442
ssdeep: 192:SL+KEGL6NQiVNDevmr5ExVEf1PxxIhuSJq3rPhIQeuAbZS:8P6uiVcvVxVwPxihLJohIQeuAZS
type: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Ursu.212383 also known as:

CynetMalicious (score: 85)
ALYacGen:Variant.Ursu.212383
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.3653
SangforTrojan.Win32.Filecoder.8
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 0055e3ef1 )
K7AntiVirusTrojan ( 0055e3ef1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.NIK
AvastFileRepMalware
BitDefenderGen:Variant.Ursu.212383
NANO-AntivirusTrojan.Win32.FileCoder.fcrxbl
MicroWorld-eScanGen:Variant.Ursu.212383
TencentWin32.Trojan.Filecoder.Swlh
Ad-AwareGen:Variant.Ursu.212383
SophosMal/Generic-S
ComodoMalware@#3tu2iuw0qp55t
BitDefenderThetaGen:NN.ZexaF.34628.aGW@a8l91Uf
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Dropper.lm
FireEyeGeneric.mg.5a5da20f88f74849
EmsisoftGen:Variant.Ursu.212383 (B)
AviraTR/FileCoder.sarli
MicrosoftTrojan:Win32/Occamy.C80
ArcabitTrojan.Ursu.D33D9F
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Ursu.212383
AhnLab-V3Malware/Win32.Generic.C2607410
McAfeeArtemis!5A5DA20F88F7
MAXmalware (ai score=95)
VBA32BScope.TrojanRansom.Genasom
MalwarebytesRansom.FileLocker
PandaTrj/GdSda.A
RisingTrojan.Filecoder!8.68 (CLOUD)
YandexTrojan.GenAsa!j8wVoRKuX+8
IkarusTrojan-Ransom.FileCrypter
FortinetW32/Filecoder.NIK!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Ursu.212383?

Ursu.212383 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment