Malware

Ursu.213654 removal guide

Malware Removal

The Ursu.213654 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.213654 virus can do?

  • Network activity detected but not expressed in API logs

How to determine Ursu.213654?


File Info:

crc32: D98A182F
md5: fbd0bfdd1b265b723bef11c0f7a13617
name: FBD0BFDD1B265B723BEF11C0F7A13617.mlw
sha1: 056044542e0d795517c28b2788f3cb6d8b610616
sha256: 1df6b3cdc7d1648585c379446304229204c586452f8886c782d6fcc8c92d6a8b
sha512: 9f00461537e990c10bd76b946feb7a23aedca4c117d4d30bc000a989714c4dcc16a4e7dfa352b72f7fcd4c32c84c244db06e44c4775ae83e661c7dda28e9d0cb
ssdeep: 3072:NfsVZqcZ3wBkVW6MPrNlo79LtH5NitqekiONiFi:GVZqA3LV6rNl09zNwkn
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: rebv2.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: rebv2
ProductVersion: 1.0.0.0
FileDescription: rebv2
OriginalFilename: rebv2.exe

Ursu.213654 also known as:

K7AntiVirusPassword-Stealer ( 0052cb021 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.DownLoader26.31549
CynetMalicious (score: 99)
ALYacGen:Variant.Ursu.213654
CylanceUnsafe
ZillyaTrojan.CoinStealer.Win32.709
SangforSuspicious.Win32.Razy.285638
CrowdStrikewin/malicious_confidence_70% (D)
K7GWPassword-Stealer ( 0052cb021 )
Cybereasonmalicious.d1b265
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/PSW.CoinStealer.CM
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.213654
NANO-AntivirusTrojan.Win32.ExtenBro.ezfuno
MicroWorld-eScanGen:Variant.Ursu.213654
TencentWin32.Trojan.Generic.Ehho
Ad-AwareGen:Variant.Ursu.213654
SophosMal/Generic-S
ComodoMalware@#8jues6ojx4g1
BitDefenderThetaGen:NN.ZemsilF.34266.hq0@a84vheb
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.fbd0bfdd1b265b72
EmsisoftGen:Variant.Ursu.213654 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1126179
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.25247B5
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Ursu.213654
AhnLab-V3Trojan/Win32.MSIL.C2640727
McAfeeGenericRXEL-RO!FBD0BFDD1B26
MAXmalware (ai score=96)
PandaTrj/GdSda.A
YandexTrojan.Agent!eVSewk3gkxk
IkarusTrojan.MSIL.PSW
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ursu.213654?

Ursu.213654 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment