Malware

Ursu.345949 information

Malware Removal

The Ursu.345949 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.345949 virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.345949?


File Info:

crc32: 8BC2C1A4
md5: 2ec28b383ab1830bd9d953b4678dda4d
name: 2EC28B383AB1830BD9D953B4678DDA4D.mlw
sha1: 7229954002fd192eba12b393a81480cf1483ddb6
sha256: 2378c8e489fc75d4efc905934ac6156e24fa1348d113a0be804fcf766eefea6b
sha512: 78fff9910de5ed859b8704bb66f4ff4b05144bcb4cb322f8911b47b5466d6c4e20555760e958f420c24e93d1e37edc1254ee884d722fa45cd4d3a3367ef5c9cd
ssdeep: 1536:YGHhl/+Y7vHFQTw9Ow1soU/DmKVvfBRisSxHjPZzem/FW:YGHP/+GvHYw9OwqoMbfBRHS5lP/FW
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: ktmw32
FileVersion: 6.1.7600.16385 (win7_rtm.090713-1255)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7600.16385
FileDescription: Windows KTM Win32 Client DLL
OriginalFilename: ktmw32
Translation: 0x0409 0x04b0

Ursu.345949 also known as:

K7AntiVirusTrojan ( 004b94ea1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader23.45375
CynetMalicious (score: 99)
CAT-QuickHealTrojan.GenericFC.S6059703
ALYacGen:Variant.Ursu.345949
CylanceUnsafe
ZillyaDropper.Generic.Win32.5403
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:MSIL/Injector.de54fe23
K7GWTrojan ( 004b94ea1 )
Cybereasonmalicious.83ab18
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.BSL
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.345949
NANO-AntivirusTrojan.Win32.Ursu.fkodwe
MicroWorld-eScanGen:Variant.Ursu.345949
TencentMalware.Win32.Gencirc.114d565f
Ad-AwareGen:Variant.Ursu.345949
SophosMal/Generic-S
ComodoMalware@#3pmdkscxfqd9
BitDefenderThetaGen:NN.ZemsilF.34294.fm3@aS56AThi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.nh
FireEyeGeneric.mg.2ec28b383ab1830b
EmsisoftGen:Variant.Ursu.345949 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.havdg
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.29970B3
MicrosoftProgram:Win32/Unwaders.C!rfn
GDataGen:Variant.Ursu.345949
AhnLab-V3Trojan/Win32.Dynamer.C2862120
McAfeeArtemis!2EC28B383AB1
MAXmalware (ai score=82)
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.Bladabindi
PandaTrj/CI.A
YandexTrojan.Agent!ZQycl5KXTsU
IkarusTrojan.MSIL.Injector
FortinetMSIL/Generic.AP.CFDAC6C!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Ursu.345949?

Ursu.345949 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment