Malware

About “Ursu.317296” infection

Malware Removal

The Ursu.317296 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.317296 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ursu.317296?


File Info:

crc32: EDC79527
md5: 00e4c2095b9f26f66e2168639e59be75
name: 00E4C2095B9F26F66E2168639E59BE75.mlw
sha1: 96a02aafb1210858f569ae8e2e5eae73961ee81d
sha256: de5fcf8cb6c6f54ac164a534389968c898e7ade61ce90f1501ad54bcc6b35f41
sha512: 037709e1e09a8d1fa9106ed5001f7dfd90dfbfa08c40a924f2f2911fcb366339dfdc203c567fb284facba7fd72654556976da761295fbe2036f6f3ea96b7ba05
ssdeep: 12288:mh1Lk70TnvjcIoDOBjUje4Gsha3vCMeSMWbR8e0w7iwKy+a0BTu:qk70Trc5DOtCEvCMepUR867iwcRu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9 2003- 2018 Apple Inc. All rights reserved.
Assembly Version: 9.8.4.0
InternalName: itunes.exe.exe
FileVersion: 3.3.9.9
CompanyName: Apple Inc.
LegalTrademarks: Apple
Comments: iTunes
ProductName: iTunes
ProductVersion: 3.3.9.9
FileDescription: iTunes
OriginalFilename: itunes.exe.exe

Ursu.317296 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Blocker.4!c
Elasticmalicious (high confidence)
McAfeeArtemis!00E4C2095B9F
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.44920
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/Blocker.d84b3c47
K7GWPassword-Stealer ( 004d8f421 )
K7AntiVirusPassword-Stealer ( 004d8f421 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/PSW.CoinStealer.AA
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Blocker.livl
BitDefenderGen:Variant.Ursu.317296
NANO-AntivirusTrojan.Win32.Blocker.fjfalc
MicroWorld-eScanGen:Variant.Ursu.317296
TencentWin32.Trojan.Blocker.Fia
Ad-AwareGen:Variant.Ursu.317296
SophosMal/Generic-S
ComodoMalware@#1880291aymvsz
BitDefenderThetaGen:NN.ZexaF.34170.Qq0@aqA0SWc
FireEyeGeneric.mg.00e4c2095b9f26f6
EmsisoftGen:Variant.Ursu.317296 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1126167
eGambitUnsafe.AI_Score_99%
ArcabitTrojan.Ursu.D4D770
ZoneAlarmTrojan-Ransom.Win32.Blocker.livl
MicrosoftBackdoor:Win32/Bladabindi!ml
Acronissuspicious
MAXmalware (ai score=100)
MalwarebytesMalware.AI.1597549510
PandaTrj/CI.A
RisingTrojan.Generic@ML.99 (RDML:C1I+fmL6o/CP9HEBlBpuOQ)
IkarusTrojan.MSIL.PSW
FortinetMSIL/CoinStealer.AA!tr.pws
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ursu.317296?

Ursu.317296 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment