Malware

Should I remove “Ursu.235079”?

Malware Removal

The Ursu.235079 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.235079 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.

Related domains:

z.whorecord.xyz
a.tomx.xyz
kral.kingx.info

How to determine Ursu.235079?


File Info:

crc32: D459A53B
md5: 05677327bbff498c07348b1a97b80d83
name: 05677327BBFF498C07348B1A97B80D83.mlw
sha1: 959bb19c9b58fb8777393a450c4ba5a8ed4bb696
sha256: 20ed27e963a3ae6a01943aae88896b127649efb42089367ad701ea896985fcdf
sha512: d1f81fc854848267f843a7ba97bd86b4217f557ca95130e4b5a2d20fbed1214444866397fb893fe1408254a5c040b366836c8ddabdf3967383733270da94c936
ssdeep: 1536:Q4cqgkeugUY80MLIKeeE/vKR1I6dIG3GubSHpdicsVMN:LcqJDgUY80MLIteE/iEkIG3Gu8pklVM
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2017 NVIDIA Corporation
Assembly Version: 0.0.0.0
InternalName: xxx.exe
FileVersion: 1.0.7.0
CompanyName: NVIDIA Corporation
Comments: NVIDIA Package Launcher
ProductName: NVIDIA Package Launcher
ProductVersion: 1.0.7.0
FileDescription: PackageLauncher
OriginalFilename: xxx.exe

Ursu.235079 also known as:

K7AntiVirusRiskware ( 0040eff71 )
Elasticmalicious (high confidence)
DrWebTrojan.Inject3.4015
CynetMalicious (score: 99)
ALYacGen:Variant.Ursu.235079
CylanceUnsafe
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_100% (D)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.7bbff4
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/Bladabindi.AS
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.235079
NANO-AntivirusTrojan.Win32.Inject3.feiaik
MicroWorld-eScanGen:Variant.Ursu.235079
TencentWin32.Trojan.Generic.Eep
Ad-AwareGen:Variant.Ursu.235079
SophosMal/Generic-S
ComodoMalware@#3l1wjccbl0ytn
BitDefenderThetaGen:NN.ZemsilF.34294.dm0@aOgE8Xd
McAfee-GW-EditionGeneric.dvb
FireEyeGeneric.mg.05677327bbff498c
EmsisoftGen:Variant.Ursu.235079 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.269E565
MicrosoftBackdoor:MSIL/Bladabindi
ArcabitTrojan.Ursu.D39647
GDataGen:Variant.Ursu.235079
McAfeeGeneric.dvb
MAXmalware (ai score=98)
MalwarebytesRiskWare.BitCoinMiner
PandaTrj/GdSda.A
IkarusTrojan-Downloader.MSIL.Tiny
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ursu.235079?

Ursu.235079 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment