Malware

Ursu.25075 removal

Malware Removal

The Ursu.25075 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.25075 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.25075?


File Info:

crc32: A63969D0
md5: afd64a8e7dd1e3bd3949471352b55cb3
name: AFD64A8E7DD1E3BD3949471352B55CB3.mlw
sha1: 6967028b8ffbecfcd7173bb84a82f72e70485213
sha256: 20f2ac2c1a194bb57f3db9d7780644efa7bb05d71f907a0b869a800fbe4d0134
sha512: 6ab68f7555b0798efc397ee529db64bb626304a354507f51ade877a67a29c886ba39800bbaa2870f45223b28fccb8f738e2da242129df72d29a232f2a2d6c949
ssdeep: 12288:wjuFxD+B6yNsEWg7LfoHujyuViSBHvcQ7V+h5jCc:wj7B6yNzW1Hujyt0Yh
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ursu.25075 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0051d2261 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.25075
CylanceUnsafe
SangforTrojan.Win32.Kryptik.FSYS
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0051d2261 )
Cybereasonmalicious.e7dd1e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.FSYS
APEXMalicious
AvastWin32:Malware-gen
BitDefenderGen:Variant.Ursu.25075
NANO-AntivirusTrojan.Win32.Kryptik.evihjg
MicroWorld-eScanGen:Variant.Ursu.25075
TencentWin32.Trojan.Crypt.Lscc
Ad-AwareGen:Variant.Ursu.25075
SophosML/PE-A
ComodoMalware@#isnxpfaajusk
BitDefenderThetaGen:NN.ZexaF.34294.FuW@aqRQmEpi
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_MiliCry-1c
McAfee-GW-EditionBehavesLike.Win32.AdwareDoma.hc
FireEyeGeneric.mg.afd64a8e7dd1e3bd
EmsisoftGen:Variant.Ursu.25075 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.ZPACK.Gen7
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Ursu.25075
AhnLab-V3Malware/Win32.Generic.C2747276
Acronissuspicious
McAfeeArtemis!AFD64A8E7DD1
VBA32BScope.TrojanSpy.Ursnif
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallMal_MiliCry-1c
RisingTrojan.Generic@ML.80 (RDML:Zd+mvK3okoNXv4i2Kp+1Bw)
YandexTrojan.Kryptik!p2Rwvz3pFFM
IkarusTrojan-Banker.UrSnif
FortinetW32/Kryptik.FSYS!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ursu.25075?

Ursu.25075 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment