Malware

Ursu.305079 removal instruction

Malware Removal

The Ursu.305079 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.305079 virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization

How to determine Ursu.305079?


File Info:

crc32: F5F5154C
md5: 75b60d0adcef2e18daae3528a4a2d1e5
name: 75B60D0ADCEF2E18DAAE3528A4A2D1E5.mlw
sha1: 14ce4785231b3193fa8c2c6a60af733ddd17e315
sha256: 7a681eb8b3e3135009ae0f8c66f5f787c6a55d2bfc126294ed04f8b1dd22835e
sha512: fcdebbc9aab49c71943b03d6504275ec1b09cc1852556633cf06fa27c9a33e51030d084811a34afe6203846c89a6e68e961b0142c86daf6fec43b29f1c1f53c7
ssdeep: 12288:Qsi8fPogHLUo6LGDJ47uM+0v4hCstQLUuGP:Qb8fPogHA5aD76E
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 2007-2017 PortableApps.com, PortableApps.com Installer 3.5.10.0
InternalName: CintaNotes Portable
PortableApps.comAppID: CintaNotesPortable
FileVersion: 3.12.0.0
PortableApps.comFormatVersion: 3.5.10
CompanyName: PortableApps.com
LegalTrademarks: PortableApps.com is a registered trademark of Rare Ideas, LLC.
Comments: For additional details, visit PortableApps.com
ProductName: CintaNotes Portable
PortableApps.comInstallerVersion: 3.5.10.0
ProductVersion: 3.12.0.0
FileDescription: CintaNotes Portable
OriginalFilename: CintaNotesPortable_3.12.paf.exe
Translation: 0x0409 0x04b0

Ursu.305079 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.305079
FireEyeGeneric.mg.75b60d0adcef2e18
Qihoo-360Win32/Trojan.Ransom.e33
McAfeeArtemis!75B60D0ADCEF
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.GandCrypt.4!c
SangforRansom.Win32.Gandcrab.MTB
K7AntiVirusTrojan ( 0053fb461 )
BitDefenderGen:Variant.Ursu.305079
K7GWTrojan ( 0053fb461 )
Cybereasonmalicious.adcef2
BitDefenderThetaGen:NN.ZexaF.34608.Nu0@a0K2Dlej
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/GenKryptik.CMML
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.GandCrypt.fpa
AlibabaRansom:Win32/GandCrypt.f6ff9086
NANO-AntivirusTrojan.Win32.GandCrypt.fincgh
ViRobotTrojan.Win32.R.Agent.647168.N
TencentWin32.Trojan.Gandcrypt.Aisc
Ad-AwareGen:Variant.Ursu.305079
SophosMal/Generic-S
ComodoMalware@#3a5fpmhhedcgg
ZillyaTrojan.GandCrypt.Win32.848
McAfee-GW-EditionBehavesLike.Win32.Dropper.jh
EmsisoftGen:Variant.Ursu.305079 (B)
GDataGen:Variant.Ursu.305079
WebrootW32.Trojan.GenKD
MAXmalware (ai score=87)
AhnLab-V3Win-Trojan/Gandcrab09.Exp
MicrosoftRansom:Win32/Gandcrab!MTB
VBA32BScope.TrojanRansom.GandCrypt
ALYacGen:Variant.Ursu.305079
PandaTrj/CI.A
RisingRansom.GandCrypt!8.F33E (CLOUD)
YandexTrojan.GandCrypt!sGXR9o7eBkU
IkarusTrojan.Win32.Krypt
FortinetW32/GenKryptik.CNMT!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Ursu.305079?

Ursu.305079 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment