Malware

Ursu.245402 removal

Malware Removal

The Ursu.245402 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.245402 virus can do?

  • Anomalous binary characteristics

How to determine Ursu.245402?


File Info:

crc32: 4CB7B6E0
md5: 0530cd49a3f668fab900f143eaee02b4
name: 0530CD49A3F668FAB900F143EAEE02B4.mlw
sha1: 09c0af51cca0aecbc0e7cade7abbf841dfc86384
sha256: 7c1a1cce7c9b28f5659e806ad9a5bae17887bdf701eb5aff862e3cc24b3f9113
sha512: ca1bd47b9b438e42304a32a6a93a727536d2d15b5bd103b808d5338c145aecc5950bf7eb8105ab897c99cbea107a9e262cca093aecbd0376f6595558fca98ba4
ssdeep: 192:L0MXz/4Xip9anPJcfLAOCiHSAoCGMuPzyQN5zB12Hi:4o44AScOCqIPfh1I
type: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: wwww.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: wwww.exe

Ursu.245402 also known as:

K7AntiVirusTrojan ( 00506efd1 )
Elasticmalicious (high confidence)
DrWebBackDoor.Meterpreter.157
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.245402
ZillyaTrojan.Rozena.Win32.116636
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:MSIL/Rozena.5cedc53a
K7GWTrojan ( 00506efd1 )
Cybereasonmalicious.9a3f66
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Rozena.B.gen
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.MSIL.Shelma.gen
BitDefenderGen:Variant.Ursu.245402
MicroWorld-eScanGen:Variant.Ursu.245402
TencentMsil.Trojan.Shelma.Dau
Ad-AwareGen:Variant.Ursu.245402
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.MSIL.SHELMA.USMANCT21
McAfee-GW-EditionRDN/Generic.rp
FireEyeGeneric.mg.0530cd49a3f668fa
EmsisoftGen:Variant.Ursu.245402 (B)
WebrootW32.Trojan.MSIL.Shelma
AviraTR/AD.MeterpreterSC.hwhzo
MicrosoftTrojan:Win32/Tiggre!rfn
AegisLabTrojan.MSIL.Shelma.4!c
ZoneAlarmHEUR:Trojan.MSIL.Shelma.gen
GDataGen:Variant.Ursu.245402
AhnLab-V3Malware/Gen.RL_Reputation.C4347736
McAfeeRDN/Generic.rp
MAXmalware (ai score=86)
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojanSpy.MSIL.SHELMA.USMANCT21
RisingTrojan.Rozena!8.6D (CLOUD)
YandexTrojan.Shelma!BVFznQmv6VM
SentinelOneStatic AI – Malicious PE
FortinetW32/Shelma.B!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.DogHousePower.HgIASRsA

How to remove Ursu.245402?

Ursu.245402 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment