Malware

Should I remove “Ursu.25940”?

Malware Removal

The Ursu.25940 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.25940 virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Ursu.25940?


File Info:

crc32: 2E994480
md5: 9aba9e2d114ba5ce353b0aed9b2d7617
name: 9ABA9E2D114BA5CE353B0AED9B2D7617.mlw
sha1: 18803ed4318118990ca1e1e5d6d56809b4d18ffa
sha256: 249db35af3d520c4ee5c7939893ad010124a74b801152e7cce00d702b958c173
sha512: 8d640bada2e54741f56642581ba33b8bb03396896ce493e653fca71bb48cece76b09b8ed4ba15888e694f51f70e02ea9f16349c45ed142e4efabd97edf87caa7
ssdeep: 1536:+pgpHzb9dZVX9fHMvG0D3XJLgdLeAyNl9XYZhVKz2MdzaPEhPZyvOsf29o41ahfK:EgXdZt9P6D3XJLceAyXYZKz2MsEt8vOD
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: (c) 2014
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.0.0
FileDescription: install
Translation: 0x0000 0x04e4

Ursu.25940 also known as:

BkavW32.AIDetect.malware2
LionicAdware.Win32.ConvertAd.2!c
Elasticmalicious (high confidence)
DrWebAdware.ClickMeIn.8035
MicroWorld-eScanGen:Variant.Ursu.25940
ALYacGen:Variant.Ursu.25940
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaAdWare:Win32/ConvertAd.500ea46e
Cybereasonmalicious.d114ba
BaiduNSIS.Adware.XXPackage.a
CyrenW32/ConvertAd.I.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32Win32/Adware.ConvertAd.AEY
APEXMalicious
AvastNSIS:ConvertAd-AG [Adw]
Kasperskynot-a-virus:HEUR:AdWare.NSIS.ConvertAd.heur
BitDefenderGen:Variant.Ursu.25940
NANO-AntivirusTrojan.Nsis.Dwn.dvttze
TencentWin32.Adware.Convertad.Hwms
Ad-AwareGen:Variant.Ursu.25940
SophosGeneric PUA BI (PUA)
ComodoApplicUnwnt@#3jw7ssv51bxji
VIPREConvertAd
McAfee-GW-EditionBehavesLike.Win32.AdwareAdload.mc
FireEyeGen:Variant.Ursu.25940
EmsisoftGen:Variant.Ursu.25940 (B)
SentinelOneStatic AI – Suspicious PE
JiangminAdWare.ConvertAd.agng
WebrootW32.Adware.Gen
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Occamy.C
ArcabitPUP.Adware.ConvertAd
SUPERAntiSpywareAdware.ConvertAds/Variant
GDataGen:Variant.Ursu.25940
AhnLab-V3PUP/Win32.ConvertAd.C4001866
McAfeeArtemis!9ABA9E2D114B
MAXmalware (ai score=99)
VBA32Adware.ConvertAd
FortinetAdware/ConvertAd
AVGNSIS:ConvertAd-AG [Adw]
Paloaltogeneric.ml

How to remove Ursu.25940?

Ursu.25940 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment