Malware

Ursu.290151 removal instruction

Malware Removal

The Ursu.290151 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.290151 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz

How to determine Ursu.290151?


File Info:

crc32: 4EB2149C
md5: cef5b890eef6ba59836c509bf0331272
name: nbys-ih.net.exe
sha1: 08a3ad54236cad0823499133265154789657d2e5
sha256: 23d59f29ec3fabb1e41da06325e4023fc2be3cb0363dc447252310a074c7cbee
sha512: c815b950f13954e1ddd11e46759c4b33449382379a89b8f95b8d9e3600fa99bea566c348de65c5d2b018e153891fb07942c8bd893ea9fc073bc0c0ec71197396
ssdeep: 49152:DoGo3n9k/mlUJ8AlcnMSlcqNhly4XWwGjnEfdmrcw/2SP8KGgERIYFjHBzuJpWB:7otk/mq+A2jy90SkKQRIY5hzUpAi
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Telif Hakkx131 xa9 2002-2015 Uludax11f Bilix15fim Ltd. x15eti.
Assembly Version: 2.0.0.55
InternalName: NBYS IH.NET.exe
FileVersion: 2.0.0.55
CompanyName: Uludax11f Bilix15fim Yazx131lx131m Departmanx131
LegalTrademarks: NBYS IH.NETx2122
Comments: NBYS IH.NET.exe.config, NBYS IH.WS.dll, NBYS AH.SM.dll
ProductName: NBYS IH.NET
ProductVersion: 2.0.0.55
FileDescription: NBYSxae x130x15f Sax11flx131x11fx131 ve Gxfcvenlix11fi
OriginalFilename: NBYS IH.NET.exe

Ursu.290151 also known as:

MicroWorld-eScanGen:Variant.Ursu.290151
FireEyeGeneric.mg.cef5b890eef6ba59
McAfeeArtemis!CEF5B890EEF6
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
BitDefenderGen:Variant.Ursu.290151
Cybereasonmalicious.0eef6b
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataGen:Variant.Ursu.290151
KasperskyTrojan.MSIL.Crypt.fzpm
AlibabaTrojan:MSIL/wnyqo.9f362501
NANO-AntivirusTrojan.Win32.Crypt.exnwyt
TencentMsil.Trojan.Crypt.Tejd
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.wnyqo
McAfee-GW-EditionArtemis!Trojan
MaxSecureTrojan.Malware.11824818.susgen
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Ursu.290151 (B)
IkarusTrojan.Crypt
JiangminTrojan.MSIL.ffex
AviraTR/Crypt.wnyqo
MAXmalware (ai score=87)
Antiy-AVLTrojan/MSIL.Crypt
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.Ursu.D46D67
AegisLabTrojan.MSIL.Crypt.4!c
ZoneAlarmTrojan.MSIL.Crypt.fzpm
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.34106.op0@auGmyme
VBA32Trojan.MSIL.Crypt
RisingTrojan.Crypt!8.2E3 (CLOUD)
YandexTrojan.Crypt!EGozhdXlCyU
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_95%
Ad-AwareGen:Variant.Ursu.290151
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Trojan.89a

How to remove Ursu.290151?

Ursu.290151 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment