Malware

Ursu.265247 removal guide

Malware Removal

The Ursu.265247 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.265247 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs

How to determine Ursu.265247?


File Info:

crc32: 4FD5FC49
md5: dd5309abb042984a46282f9597d7a504
name: DD5309ABB042984A46282F9597D7A504.mlw
sha1: 5bbbadcabb624a2ae5607d2ce34d0569227873a6
sha256: 236e677c493fa5e6084a31bcce5347d5ae867ba822fc3fed00db5b873a88390d
sha512: e915fa84fe830cfcbb095f49fc02ce264e4f265f353b5ddb1774fb0e521cc6691c8b06b92015d60fa3ce2fa15aec46c218ff10adfa7a24594c6a15636a0fb5bb
ssdeep: 1536:cVUtssYfbw7PUwEt6HoB7GBnor2H94wDfnbVDQkeUG1DCOSlOPTkeP4mSGa2n:RqoaNNorLhrhsPTkVTGZ
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 9.9.407.4417
InternalName: VVBchpp.exe
FileVersion: 9.9.407.4417
CompanyName: qGKLHa
Comments: WkvWHn
ProductName: JJtfVFdafC
ProductVersion: 9.9.407.4417
FileDescription: WkvWHn
OriginalFilename: VVBchpp.exe

Ursu.265247 also known as:

K7AntiVirusTrojan ( 004df8ab1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Starter.5939
ALYacGen:Variant.Ursu.265247
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.147620
SangforTrojan.Win32.Generic.ky
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:MSIL/Injector.70ee65cb
K7GWTrojan ( 004df8ab1 )
Cybereasonmalicious.bb0429
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.OIK
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.265247
NANO-AntivirusTrojan.Win32.CTR30086hq0.fgbpbp
MicroWorld-eScanGen:Variant.Ursu.265247
TencentWin32.Trojan.Generic.Wtdj
Ad-AwareGen:Variant.Ursu.265247
SophosMal/Generic-S
ComodoMalware@#1mmz6yvfb4ub3
BitDefenderThetaAI:Packer.A5D573DF25
McAfee-GW-EditionArtemis
FireEyeGeneric.mg.dd5309abb042984a
EmsisoftGen:Variant.Ursu.265247 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.duadx
AviraHEUR/AGEN.1105295
Antiy-AVLTrojan/Generic.ASMalwS.272834E
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataGen:Variant.Ursu.265247
McAfeeArtemis!DD5309ABB042
MAXmalware (ai score=87)
PandaTrj/GdSda.A
IkarusTrojan.MSIL.Injector
FortinetMSIL/Injector.OBY!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Ursu.265247?

Ursu.265247 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment