Malware

Ursu.300718 removal guide

Malware Removal

The Ursu.300718 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.300718 virus can do?

  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.300718?


File Info:

crc32: 29F6E8BF
md5: 72ef47e3baa4f9bf2d0d7058d35a49e4
name: 72EF47E3BAA4F9BF2D0D7058D35A49E4.mlw
sha1: 885141708fd6cc966f087d2bc529fbd85b0adc7f
sha256: 1a11f4e76341950c1301e883f69b222582d5ab9fda19e504729d9c9401732680
sha512: 9f4a2c8a05f372dda0ca90bb733105626668f57bfaf5c83d332fcd23194fb57840b5690886ccdd1baf4914af31d451de1d66a2c082233d4e42d8fad7c9422305
ssdeep: 48:6z+e0Wr36ruJliAlxgq5eeO+3gcX/hzggYsSfbNtm:FbKtxf5zIzNt
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 assertiveness 2015
Assembly Version: 4.9.4.20
InternalName: amparo.exe
FileVersion: 4.9.4.20
CompanyName: assertiveness
LegalTrademarks: xa9 2015 assertiveness
Comments: assertiveness
ProductName: assertiveness
ProductVersion: 4.9.4.20
FileDescription: assertiveness
OriginalFilename: amparo.exe

Ursu.300718 also known as:

K7AntiVirusAdware ( 0052b2131 )
LionicTrojan.Win32.DotDo.4!c
ALYacGen:Variant.Ursu.300718
CylanceUnsafe
ZillyaAdware.Dotdo.Win32.34375
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Ursu.300718
K7GWAdware ( 0052b2131 )
Cybereasonmalicious.3baa4f
CyrenW32/MSIL_Troj.ACC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Adware.Dotdo.CP
APEXMalicious
AlibabaAdWare:MSIL/Dotdo.3a714721
NANO-AntivirusRiskware.Win32.Dotdo.fiffcz
MicroWorld-eScanGen:Variant.Ursu.300718
TencentMsil.Adware.Dotdo.Aisl
Ad-AwareGen:Variant.Ursu.300718
SophosGeneric PUA II (PUA)
ComodoApplication.MSIL.Dotdo.CP@7xj8xg
VIPREAdware.DotDo
McAfee-GW-EditionArtemis!PUP
FireEyeGen:Variant.Ursu.300718
EmsisoftGen:Variant.Ursu.300718 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1110023
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Ursu.D496AE
GDataGen:Variant.Ursu.300718
McAfeeArtemis!72EF47E3BAA4
MAXmalware (ai score=85)
MalwarebytesAdware.DotDo.Generic
PandaTrj/CI.A
YandexPUA.Dotdo!IWpmzDJE4Wg
IkarusAdWare.Dotdo
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/Dotdo

How to remove Ursu.300718?

Ursu.300718 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment