Malware

Should I remove “Ursu.317548”?

Malware Removal

The Ursu.317548 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.317548 virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

kapuapkope.lv

How to determine Ursu.317548?


File Info:

crc32: 29DF7C45
md5: 96d9409d919e1f7b99e7cb2920b4aaa1
name: 96D9409D919E1F7B99E7CB2920B4AAA1.mlw
sha1: d60da8d6b85cadae61d5209a195ff74716be0a84
sha256: c67cb1c3288c1eb143bc25c5f7f43085917bef125429504113abe4fc6b97d604
sha512: 3ed23757a7f58231d69ac8ae2806a132c7c79e52e1e3b91dffb7cf8354b45c9724b20f10c4990b46dcfeb33477596033d98a216be5a0a847192b403cc4ec847d
ssdeep: 3072:O1P68FrwHN3wH6Hiokvw3NcesIq+9g5o9TKUVGwCXbO5pcH0T0j04+dysg49zn5:TcH0Uvw3Nc/Iq+9g5owbO5pcUwjcIn
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2000
InternalName: dmcr
FileVersion: 1, 0, 0, 1
CompanyName: -GSC-
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: -GSC- dmcr
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: dmcr
OriginalFilename: dmcr.exe
Translation: 0x0419 0x04b0

Ursu.317548 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Coins.4!c
Elasticmalicious (high confidence)
ALYacGen:Variant.Ursu.317548
CylanceUnsafe
ZillyaTrojan.Coins.Win32.1757
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojanPSW:Win32/Coins.2cca35d3
K7GWTrojan ( 0053fb461 )
K7AntiVirusTrojan ( 0053fb461 )
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.GNHR
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win32.Coins.mrl
BitDefenderGen:Variant.Ursu.317548
NANO-AntivirusTrojan.Win32.Inject.fjawdl
MicroWorld-eScanGen:Variant.Ursu.317548
TencentMalware.Win32.Gencirc.1149278d
Ad-AwareGen:Variant.Ursu.317548
SophosMal/Generic-R + Mal/Kryptik-CY
ComodoMalware@#2hk2d7a9tvzgy
BitDefenderThetaGen:NN.ZexaF.34058.Iu0@aGEDhCbk
TrendMicroTrojan.Win32.AZORULT.CBQ
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.96d9409d919e1f7b
EmsisoftGen:Variant.Ursu.317548 (B)
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_81%
MicrosoftRansom:Win32/Gandcrab!MTB
ArcabitTrojan.Ursu.D4D86C
GDataGen:Variant.Ursu.317548
AhnLab-V3Win-Trojan/Gandcrab09.Exp
Acronissuspicious
McAfeeArtemis!96D9409D919E
VBA32Trojan.Inject
MalwarebytesTrojan.Injector
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.AZORULT.CBQ
YandexTrojan.GenAsa!z9dJbmjgUFs
IkarusTrojan.Win32.Injector
FortinetW32/GenKryptik.CKDY!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HwcBEpsA

How to remove Ursu.317548?

Ursu.317548 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment