Malware

What is “Ursu.222567”?

Malware Removal

The Ursu.222567 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.222567 virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.222567?


File Info:

crc32: CBBC0DE1
md5: eb8bf9de8ed605a79f3b4834ee654fda
name: EB8BF9DE8ED605A79F3B4834EE654FDA.mlw
sha1: 2952322495eb41003dc8b97859d5a97bdde9251d
sha256: 0521bb85472869598d9aa822b11edc04044dbe876dbf9900565bfdc8e02c2b21
sha512: d2d6f590c391ecfe9ad1a08023c06cce661836216d116695adeb6df660377eb87026af6302b28fffad417faea39282c46a19c45fa0ad2790486448d6968cb307
ssdeep: 1536:wcKfnSXceuWT7xF7E7eQ43LbNMkjMQynuQRwPV:18SXce7TlF7Ei/3VVGC
type: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: output.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: output.exe

Ursu.222567 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.StealerNET.101
ClamAVWin.Packed.Bulz-9868353-0
ALYacGen:Variant.Ursu.222567
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
CyrenW32/MSIL_Agent.BJO.gen!Eldorado
ESET-NOD32a variant of MSIL/PSW.Agent.SHS
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-PSW.MSIL.Agent.gen
BitDefenderGen:Variant.Ursu.222567
MicroWorld-eScanGen:Variant.Ursu.222567
Ad-AwareGen:Variant.Ursu.222567
SophosML/PE-A + Troj/MSIL-RJM
BitDefenderThetaGen:NN.ZemsilF.34088.jm0@amFHcil
McAfee-GW-EditionGenericRXOT-FK!EB8BF9DE8ED6
FireEyeGeneric.mg.eb8bf9de8ed605a7
EmsisoftGen:Variant.Ursu.222567 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1143802
eGambitUnsafe.AI_Score_98%
MicrosoftPWS:MSIL/Mercurial.GA!MTB
ArcabitTrojan.Ursu.D36567
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agent.gen
GDataMSIL.Trojan.PSE.17J45VV
AhnLab-V3Trojan/Win.Generic.C4555074
McAfeeGenericRXOT-FK!EB8BF9DE8ED6
MAXmalware (ai score=82)
MalwarebytesSpyware.DiscordStealer
PandaTrj/GdSda.A
RisingStealer.Mercurial!1.D7B6 (CLASSIC)
IkarusTrojan.MSIL.Spy
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/PSW.4C4A!tr
AVGWin32:MalwareX-gen [Trj]

How to remove Ursu.222567?

Ursu.222567 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment