Malware

Ursu.366167 (file analysis)

Malware Removal

The Ursu.366167 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.366167 virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ursu.366167?


File Info:

crc32: 41218632
md5: c6096e5348e15f88425e41e5fa34e50b
name: C6096E5348E15F88425E41E5FA34E50B.mlw
sha1: 537b49386efa32a7186a732cf7caf0301441760b
sha256: 69625c9bb745c2ed51992728f870f6f2ec82eef405469d05c0e952b2a444f1d2
sha512: 55f6689bd7c9e6573f837beb76543f117dd0ad54b3e21fdc8c205d33cb94a4db2f9e88ccfb92b53bf43a34f812e921340afa3c5b6272c43906381f5882bd716a
ssdeep: 3072:ow4gnScGuDI2dc6Hn3aJEdvEUCe1jXZ/cYVtSN9fEl+TsTxYRFu7Pm7zlX5:oz2ZqJE5jNXZUTN9fbaxk3t5
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: devenv.exe
FileVersion: 15.0.26228.9 built by: D15RTWSVC
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Visual Studioxae
ProductVersion: 15.0.26228.9
FileDescription: Microsoft Visual Studio 2017
OriginalFilename: devenv.exe
Translation: 0x0409 0x04b0

Ursu.366167 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusPassword-Stealer ( 0052f9a71 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.24814
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Gandcrab
ALYacGen:Variant.Ursu.366167
CylanceUnsafe
SangforTrojan.Win32.Gandcrab.S
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanPSW:Win32/Gandcrab.4f493fa6
K7GWPassword-Stealer ( 0052f9a71 )
Cybereasonmalicious.348e15
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/PSW.Delf.OSF
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.366167
NANO-AntivirusTrojan.Win32.Stealer.fmynah
MicroWorld-eScanGen:Variant.Ursu.366167
Ad-AwareGen:Variant.Ursu.366167
McAfee-GW-EditionBehavesLike.Win32.Dropper.dc
FireEyeGen:Variant.Ursu.366167
EmsisoftGen:Variant.Ursu.366167 (B)
WebrootW32.Trojan.Emotet
AviraHEUR/AGEN.1127501
MicrosoftTrojan:Win32/Gandcrab.S!MTB
GDataGen:Variant.Ursu.366167
AhnLab-V3Malware/Gen.Generic.C2807766
McAfeeRDN/Generic PWS.y
VBA32TrojanPSW.Stealer
PandaTrj/CI.A
RisingTrojan.Injector/NSIS!1.BFBB (CLASSIC)
IkarusTrojan.NSIS.Injector
FortinetW32/Injector.AFV!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ursu.366167?

Ursu.366167 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment