Malware

Ursu.236861 (file analysis)

Malware Removal

The Ursu.236861 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.236861 virus can do?

  • Anomalous binary characteristics

How to determine Ursu.236861?


File Info:

crc32: 62367E2C
md5: eb0664beac0a3487c47a675b7597fa7e
name: EB0664BEAC0A3487C47A675B7597FA7E.mlw
sha1: 6a25c0d91c5a96ef89bc30e969bfed63b1c01ea3
sha256: 19dcab2aa267514b89d971ad9623b473fad05b9137d33928e476856094863425
sha512: 26191c89ddd3f6201a9f2bd6e27a589d2b1548a3034336f0e43c62f5f85081865df375ebe184bd3ae63778ce46f295ab1fbb60893ae39f1eabc9f5fc93ef916d
ssdeep: 384:IDYFEWGXS7mrL0nZwYjHGLGbCLpwfE8dD4:Ik6NXSCvgGMCLpcB
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2016
Assembly Version: 1.0.0.0
InternalName: SendingMail.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: SendingMail
ProductVersion: 1.0.0.0
FileDescription: SendingMail
OriginalFilename: SendingMail.exe

Ursu.236861 also known as:

K7AntiVirusPassword-Stealer ( 0055e3ee1 )
LionicTrojan.MSIL.Small.i!c
CynetMalicious (score: 99)
ALYacGen:Variant.Ursu.236861
CylanceUnsafe
ZillyaTrojan.Small.Win32.34953
SangforTrojan.Win32.Agent.8
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:MSIL/Generic.7b54e9cb
K7GWPassword-Stealer ( 0055e3ee1 )
Cybereasonmalicious.eac0a3
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/PSW.Agent.PWV
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-PSW.MSIL.Small.k
BitDefenderGen:Variant.Ursu.236861
NANO-AntivirusTrojan.Win32.Agent.ehuotw
ViRobotTrojan.Win32.Z.Razy.15872.DV
MicroWorld-eScanGen:Variant.Ursu.236861
TencentMsil.Trojan-qqpass.Qqrob.Ajle
Ad-AwareGen:Variant.Ursu.236861
SophosMal/Generic-S
ComodoMalware@#1sy2suox643iz
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0PJV21
McAfee-GW-EditionGenericRXBR-VR!EB0664BEAC0A
FireEyeGen:Variant.Ursu.236861
EmsisoftGen:Variant.Ursu.236861 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1130863
eGambitUnsafe.AI_Score_98%
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Ursu.D39D3D
GDataGen:Variant.Ursu.236861
McAfeeGenericRXBR-VR!EB0664BEAC0A
MAXmalware (ai score=82)
VBA32TScope.Trojan.MSIL
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0PJV21
YandexTrojan.PWS.Agent!X/ke8l9FiKc
IkarusTrojan.MSIL.PSW
FortinetMSIL/Agent.PWV!tr.pws
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ursu.236861?

Ursu.236861 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment