Malware

Ursu.375411 removal instruction

Malware Removal

The Ursu.375411 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.375411 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Installs itself for autorun at Windows startup
  • Harvests information related to installed instant messenger clients
  • Makes SMTP requests, possibly sending spam or exfiltrating data.
  • Anomalous binary characteristics

Related domains:

www.prodigyproductionsllc.com
survey-smiles.com
smtp.mail.yahoo.com

How to determine Ursu.375411?


File Info:

crc32: 81E0E5B2
md5: 774bfd6122f6fb914859ad3cf93ca233
name: 774BFD6122F6FB914859AD3CF93CA233.mlw
sha1: 990cc8b74da2bd9ffee86cc89f8927f9ed642fb2
sha256: 2cdf50eb103013ac071c258532f1813676045e4a28e9db9666726bf8feaea5b6
sha512: 46c05d186525c3215a8ea73a9a73d057e40a2756a91ce6fc82dbe54bc3ecfcb568c4c0b6325f0263bfb43585ffbc310140e19e62977d2a6493cdc43433730d82
ssdeep: 12288:xq+g88qNxbgs5dXOaaNGjrsNmp7tkkRJe5Lo2ynt/lrgDjKNLS1w541rAMpmVGD:49Ys6OaaMssppTRJ6LofeDjD1wLq
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ursu.375411 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader11.12386
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.375411
CylanceUnsafe
CrowdStrikewin/malicious_confidence_80% (D)
Cybereasonmalicious.122f6f
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Ursu.375411
NANO-AntivirusTrojan.Win32.Mlw.fgxtwi
MicroWorld-eScanGen:Variant.Ursu.375411
TencentWin32.Trojan.Generic.Agvb
ComodoMalware@#k7vigqu3yxc7
McAfee-GW-EditionBehavesLike.Win32.AdwareAdload.bc
FireEyeGeneric.mg.774bfd6122f6fb91
EmsisoftGen:Variant.Ursu.375411 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Agent.1219584.18
Antiy-AVLTrojan/Generic.ASMalwS.14DD023
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ursu.375411
McAfeeArtemis!774BFD6122F6
MAXmalware (ai score=88)
YandexTrojan.Agent!WGyo5eH7B1w
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ursu.375411?

Ursu.375411 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment