Malware

What is “Ursu.301819”?

Malware Removal

The Ursu.301819 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.301819 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.301819?


File Info:

crc32: BFE410CD
md5: 26583815f43f28f4099415c38d7753a0
name: 26583815F43F28F4099415C38D7753A0.mlw
sha1: 2d76fe9069c54c4ac0556281e237c52861e8988e
sha256: b820f2d7b28fb40a2894ad6e0a8c1e4d58503928b53755b03840f4586a76809c
sha512: f5d4fd1f8b775d96b1e413f939d9c7558225e0564b427e57bc6907b9a5b4111f7513acf59a79c68db8cfdd64e18b501c850f409a52f37af155864fd026ec90eb
ssdeep: 12288:Qlt00TaWKsWeR5C8tOjY97iQYzGpXPNuMxNosgwEp9:WTjJWeR5IGiQY8XLxu+C
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 1999 - 2014 LiteManagerTeam
CompanyName: LiteManagerTeam
FileDescription: Meadows Expressins Resilient
LegalTrademarks: Copyright xa9 1999 - 2014 LiteManagerTeam
Comments: Meadows Expressins Resilient
ProductName: Supervisor Labway
ProductVersion: 6.8.91.4
PrivateBuild: 6.8.91.4
OriginalFilename: Supervisor Labway
Translation: 0x0409 0x04b0

Ursu.301819 also known as:

K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.Encoder.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.26686
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Hermes
CylanceUnsafe
ZillyaAdware.Encoder.Win32.1
SangforTrojan.Win32.MalwareCrypter.rkuyh
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Hermez.6642a1fe
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.5f43f2
ESET-NOD32a variant of Win32/Kryptik.FOBW
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.Hermez.gm
BitDefenderGen:Variant.Ursu.301819
NANO-AntivirusTrojan.Win32.Encoder.fihffa
MicroWorld-eScanGen:Variant.Ursu.301819
TencentWin32.Trojan.Encoder.Hqbw
Ad-AwareGen:Variant.Ursu.301819
SophosMal/Generic-S
ComodoMalware@#1l8pnsgz1jz07
BitDefenderThetaGen:NN.ZexaF.34790.Gu0@aeVSetbi
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.26583815f43f28f4
EmsisoftGen:Variant.Ursu.301819 (B)
AviraHEUR/AGEN.1117382
Antiy-AVLTrojan/Generic.ASMalwS.2819CD9
MicrosoftTrojan:Win32/Occamy.C
GDataGen:Variant.Ursu.301819
TACHYONRansom/W32.Encoder.525824
McAfeeArtemis!26583815F43F
MAXmalware (ai score=72)
PandaTrj/RnkBend.A
YandexTrojan.Encoder!v9zwKvX1H/4
IkarusTrojan-Spy.Remcos
FortinetW32/Kryptik.FOBW!tr.ransom
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HgIASQwA

How to remove Ursu.301819?

Ursu.301819 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment