Malware

Ursu.270951 information

Malware Removal

The Ursu.270951 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.270951 virus can do?

  • Unconventionial language used in binary resources: Korean
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs

How to determine Ursu.270951?


File Info:

crc32: F5ADC787
md5: 4dcb221d12a961428a095caf27899bde
name: 4DCB221D12A961428A095CAF27899BDE.mlw
sha1: bff3c6af4efe4cea6e78bfabdc3a7bb413cf1d23
sha256: 1de47239b10dab9957807b759e0337b87a29fa72ddd6243df37fcb0c6555bd28
sha512: c6989bb98d8af94d171ffc7d7addab203a6dc84b123f28c96fc59591fec5db94f30c17e1ae2413eec83ec7e018964fe2f25d5b5b77dbbf4f5ffa7093ed8d0217
ssdeep: 49152:QC0jkPU6k4T6rdo3sByrhDlWvwMO6HQoAEIZamMYthO8qGN:QI8V4T6rdo8B4hDcoMOWILRh
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: DOOMx64
InternalName: DOOMx64.exe
FileVersion: 1.0.0.1
CompanyName: DOOMx64
ProductName: DOOMx64
ProductVersion: 1.0.0.1
FileDescription: DOOMx64
OriginalFilename: DOOMx64.exe
Translation: 0x0412 0x03b5

Ursu.270951 also known as:

K7AntiVirusTrojan ( 00539d6b1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.Ursu.270951
CylanceUnsafe
ZillyaTrojan.Agent.Win32.928155
SangforTrojan.Win32.Agent.soudx
AlibabaTrojan:Win32/Generic.bc0400b0
K7GWTrojan ( 00539d6b1 )
Cybereasonmalicious.d12a96
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Agent.ZVC
APEXMalicious
AvastFileRepMalware
KasperskyTrojan.Win32.Agent.qwhdsv
BitDefenderGen:Variant.Ursu.270951
NANO-AntivirusTrojan.Win32.Mikey.fixuat
MicroWorld-eScanGen:Variant.Ursu.270951
TencentMalware.Win32.Gencirc.114d356d
Ad-AwareGen:Variant.Ursu.270951
SophosMal/Generic-S
ComodoMalware@#158sjinqnh81v
BitDefenderThetaGen:NN.ZexaE.34266.Cw0@a4J2o0mG
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
FireEyeGen:Variant.Ursu.270951
EmsisoftGen:Variant.Ursu.270951 (B)
JiangminTrojan.Agent.bnjz
AviraTR/Agent.soudx
Antiy-AVLTrojan/Generic.ASMalwS.2756FE3
MicrosoftTrojan:Win32/Occamy.C1D
ArcabitTrojan.Ursu.D42267
GDataGen:Variant.Ursu.270951
McAfeeArtemis!4DCB221D12A9
MAXmalware (ai score=100)
MalwarebytesMachineLearning/Anomalous.94%
PandaTrj/CI.A
RisingTrojan.Generic@ML.80 (RDML:iEdTOWTAc4e36Jpx94TYbw)
YandexTrojan.GenAsa!snPJjlnxZ84
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.4183C3
AVGFileRepMalware

How to remove Ursu.270951?

Ursu.270951 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment