Malware

Ursu.352112 removal guide

Malware Removal

The Ursu.352112 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.352112 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Ursu.352112?


File Info:

crc32: 7E7E1821
md5: 66e936face51f3d8d6f33cf7f228ff72
name: 66E936FACE51F3D8D6F33CF7F228FF72.mlw
sha1: 6cbb93de143676e92b0eb551af0656a403f22b9d
sha256: 1a0f2846242b893fdeeef8782d7b1394a657bcb34c717d8742859ef91852d0e2
sha512: ce6bce92b483c0fa6d501e21425de5295255ad19c5813688694b32d6537899010d621d9b4546e482a7ee148a86eef84505012de689130e4a6d851008bb3d8aea
ssdeep: 3072:qw09RtYNRW1/ebWPH5ZLRTgULTX9AQwg7Op2X2+Y0B7kieR:Z8I2/fTWUnNxOp2TBgi
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: xb370xc2a4xd06cxd1b1 xcc3d xad00xb9acxc790
Assembly Version: 0.0.0.0
InternalName: War3.exe
FileVersion: 0
ProductName: xb370xc2a4xd06cxd1b1 xcc3d xad00xb9acxc790
ProductVersion: 0
FileDescription: xb370xc2a4xd06cxd1b1 xcc3d xad00xb9acxc790
OriginalFilename: War3.exe
Translation: 0x0000 0x04b0

Ursu.352112 also known as:

K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.Win32.AntiAV.4!c
DrWebBackDoor.Bladabindi.13678
McAfeeGenericRXEC-LC!66E936FACE51
CylanceUnsafe
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.ace51f
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.TJZ
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyTrojan.Win32.AntiAV.cqpw
BitDefenderGen:Variant.Ursu.352112
NANO-AntivirusTrojan.Win32.AntiAV.exykfw
MicroWorld-eScanGen:Variant.Ursu.352112
TencentWin32.Trojan.Antiav.Wrgz
Ad-AwareGen:Variant.Ursu.352112
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34236.im0@ayt6F2h
McAfee-GW-EditionGenericRXEC-LC!66E936FACE51
FireEyeGeneric.mg.66e936face51f3d8
EmsisoftGen:Variant.Ursu.352112 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.caozr
AviraHEUR/AGEN.1128436
Antiy-AVLTrojan/Generic.ASMalwS.2464E70
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Ursu.D55F70
ZoneAlarmTrojan.Win32.AntiAV.cqpw
GDataGen:Variant.Ursu.352112
AhnLab-V3Trojan/Win32.Korat.R219681
VBA32TScope.Trojan.MSIL
MAXmalware (ai score=86)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
IkarusTrojan.MSIL.CryptoObfuscator
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Injector.TJZ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ursu.352112?

Ursu.352112 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment