Malware

How to remove “Ursu.216192”?

Malware Removal

The Ursu.216192 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.216192 virus can do?

  • Unconventionial language used in binary resources: Indonesian
  • Network activity detected but not expressed in API logs

How to determine Ursu.216192?


File Info:

crc32: A8E77CB9
md5: ffd5ac4a81ab318479630ae92a16afb0
name: FFD5AC4A81AB318479630AE92A16AFB0.mlw
sha1: e44b59ceccb8b583e44a35e9563ba2b126f4508f
sha256: 06f669e396477ee48a83e8ed98f49ec49ee5f4d129de7cd6e120591f2e72f52f
sha512: b9497458e9958322fb5855c8128b763011801a1bac9cf4217602e5b8b739e5b66712b8d78a2484ed3544c71b34681f108d009bb218bdce5e1af4079198520aed
ssdeep: 12288:mgrOrANN8pbikuAfNnlTDsXHWEHwNaSctMX:AgOfL/sXHWEpM
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright (C) Synaptics Incorporated 1996-2015
InternalName: Zmeter2
FileVersion: 19.0.12.98 28Jul15
CompanyName: Synaptics Incorporated
ProductName: Synaptics Pointing Device Driver
ProductVersion: 19.0.12.98 28Jul15
FileDescription: Synaptics Pressure Graph
OriginalFilename: Zmeter2.exe
Translation: 0x0409 0x04b0

Ursu.216192 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.216192
ALYacGen:Variant.Ursu.216192
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Kryptik.ali2000016
Cybereasonmalicious.a81ab3
BitDefenderThetaGen:NN.ZemsilF.34236.Nm0@aekGftfG
SymantecScr.Malcode!gdn33
ESET-NOD32a variant of MSIL/Kryptik.ACKH
APEXMalicious
AvastWin32:PWSX-gen [Trj]
CynetMalicious (score: 100)
KasperskyVHO:Trojan.MSIL.Injuke.gen
BitDefenderGen:Variant.Ursu.216192
Ad-AwareGen:Variant.Ursu.216192
FireEyeGeneric.mg.ffd5ac4a81ab3184
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_65%
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Ursu.216192
MAXmalware (ai score=81)
IkarusTrojan.MSIL.Injector
FortinetMSIL/Kryptik.ACKH!tr
AVGWin32:PWSX-gen [Trj]

How to remove Ursu.216192?

Ursu.216192 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment