Malware

Ursu.26919 removal

Malware Removal

The Ursu.26919 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.26919 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.26919?


File Info:

crc32: 8F7918A6
md5: a4071558e629ddfffca97fedb8434812
name: A4071558E629DDFFFCA97FEDB8434812.mlw
sha1: 135d4ff606c6b11e9e4ba0b1dfc5c9e6410d4c8a
sha256: 39bcbe572b5c3c0c699f71510e0c1709cf419c3edc84dd7c5dbd3e48ab98b4d0
sha512: 56496ecf8071422fa0e3fa37a8061bd3a6f128702e338c77331424540186ceff92ead27639b601c9497466495a096ef885e75154a7f1ef1290fa244fa4bf0a31
ssdeep: 3072:3Bu46ewVlCkHMouPF5BpnlkPSbrrWx/VWZ/pTvjtqZvpzbyW4JXyCPJO6stiNO4:84UrHMo0pnjrrWhwZ/JjiNypCCc6g
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 1BN Software & IT Solutions Copyright (c) 2006-2014
CompanyName: 1BN Software & IT Solutions
LegalTrademarks: 1BN Software & IT Solutions Copyright (c) 2006-2014
Comments: Striped Adaptive Proofreading
ProductName: Medieval
ProductVersion: 3.5.69.8
FileDescription: Striped Adaptive Proofreading
OriginalFilename: Medieval.exe
Translation: 0x0409 0x04b0

Ursu.26919 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004f733b1 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3953
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.26919
CylanceUnsafe
ZillyaTrojan.Crusis.Win32.853
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004f733b1 )
Cybereasonmalicious.8e629d
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.Crysis.H
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Crusis.bgl
BitDefenderGen:Variant.Ursu.26919
NANO-AntivirusTrojan.Win32.Crusis.ewlpvj
MicroWorld-eScanGen:Variant.Ursu.26919
TencentWin32.Trojan.Crusis.Lizv
Ad-AwareGen:Variant.Ursu.26919
SophosMal/Generic-S
ComodoMalware@#5pho0ufcm10h
BitDefenderThetaGen:NN.ZexaF.34058.zu0@auHrAyoi
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_Cerber-3
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.a4071558e629ddff
EmsisoftGen:Variant.Ursu.26919 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1130769
eGambitUnsafe.AI_Score_96%
Antiy-AVLTrojan/Generic.ASMalwS.22CE5DE
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Troldesh.C
ArcabitTrojan.Ursu.D6927
ZoneAlarmTrojan-Ransom.Win32.Crusis.bgl
GDataGen:Variant.Ursu.26919
Acronissuspicious
McAfeeArtemis!A4071558E629
VBA32BScope.TrojanRansom.Locky
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_Cerber-3
RisingTrojan.Generic@ML.94 (RDML:ivaUwVcIpbglq2HksUAjbA)
YandexTrojan.Crusis!MEYy0glVqgw
IkarusTrojan-Ransom.Crusis
FortinetW32/Crusis.BGL!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.CrySiS.HgIASSEA

How to remove Ursu.26919?

Ursu.26919 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment