Malware

What is “Ursu.263917”?

Malware Removal

The Ursu.263917 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.263917 virus can do?

  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Queries information on disks, possibly for anti-virtualization

Related domains:

csdw.jia-si.cn

How to determine Ursu.263917?


File Info:

crc32: 289A7BB3
md5: 2aa7f2459598c9f86cea63f9f73c9796
name: 2AA7F2459598C9F86CEA63F9F73C9796.mlw
sha1: 941474f73d11b5ea7b12c10efc13af3083217939
sha256: 1df9a1bf918b2a670df3f58519554b0f20cd5355252b24463f1ad64348add7cb
sha512: 78ca4ca7dc6578a10c5b6cc66ce0ea57c6dc39008a19d5f4fbcba889dfc6c6df203fbe77e2bd2784da71b56731dc3002f231582b778c4b08687fb0bb8f1fe268
ssdeep: 49152:aUJl/bKjFvnlPlqtljsESPkKB9uaLHQIjKGvr16j/GsmhQq87eL3u:aUJBaFfplqgxB9hLWAhQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ursu.263917 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusAdware ( 005631911 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.5487
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Skeeyah.S3293683
ALYacGen:Variant.Ursu.263917
CylanceUnsafe
ZillyaTrojan.Generic.Win32.150659
K7GWAdware ( 005631911 )
Cybereasonmalicious.59598c
CyrenW32/S-c1d17122!Eldorado
SymantecPUA.Downloader
ESET-NOD32a variant of Win32/Softcnapp.BC potentially unwanted
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.263917
NANO-AntivirusTrojan.Win32.Softcnapp.fhyrfu
MicroWorld-eScanGen:Variant.Ursu.263917
TencentTrojan.Win32.Generic.e
Ad-AwareGen:Variant.Ursu.263917
SophosSoftcnapp (PUA)
ComodoApplication.Win32.AdWare.Softcnapp.G@7x13gz
BitDefenderThetaGen:NN.ZexaF.34266.LAW@a0tu1jej
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Softcnapp.vh
FireEyeGeneric.mg.2aa7f2459598c9f8
EmsisoftGen:Variant.Ursu.263917 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.cmtwm
AviraHEUR/AGEN.1142834
eGambitUnsafe.AI_Score_98%
Antiy-AVLTrojan/Generic.ASMalwS.273C865
MicrosoftPUA:Win32/Softcnapp
GDataGen:Variant.Ursu.263917
AhnLab-V3PUP/Win32.Helper.R233980
Acronissuspicious
McAfeeSoftcnapp
MAXmalware (ai score=100)
VBA32BScope.Adware.Puwaders
MalwarebytesMalware.AI.4241390579
PandaTrj/Genetic.gen
RisingAdware.Downloader!1.BBEC (CLASSIC)
YandexTrojan.GenAsa!m+51rBERkto
IkarusPUA.Softcnapp
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Ursu.263917?

Ursu.263917 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment