Malware

Ursu.380799 removal guide

Malware Removal

The Ursu.380799 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.380799 virus can do?

  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Uses suspicious command line tools or Windows utilities

How to determine Ursu.380799?


File Info:

crc32: A222392B
md5: fc23de05f430e2a161f13a2a2fc7e646
name: FC23DE05F430E2A161F13A2A2FC7E646.mlw
sha1: 04f1c76fa1b860212cf08a44bc19b120c1d3b170
sha256: 8ff5d4d6849593fc5eed07e70388684f874264e464ab84d8205fd864348bffbf
sha512: 763ff76f0c3cea3ecc10582ddf9b5b8bbab212030d62e8b19b016cf8d2a1769bdd325213f74939a0935bff99c0c2dcbc7b3b2aee6b2ead8bc940943ea67d3759
ssdeep: 6144:nDIxiqpPBC3bEGxgj7vyvedFJxIwMM/BnRCinPHCgL9RxpM/yVtOgj7oS:n0QqpJC3AGxkxFMMJn/HtRvM/Qg87oS
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Ursu.380799 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Gen.4!c
CAT-QuickHealRansom.Kraken.S4954668
ALYacGen:Variant.Ursu.380799
CylanceUnsafe
ZillyaTrojan.Gen.Win32.1930
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaRansom:Win32/Filecoder.973931e8
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.NUC
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Gen.kwa
BitDefenderGen:Variant.Ursu.380799
NANO-AntivirusTrojan.Win32.Filecoder.fmefap
MicroWorld-eScanGen:Variant.Ursu.380799
TencentWin32.Trojan.Gen.Ednf
Ad-AwareGen:Variant.Ursu.380799
SophosGeneric ML PUA (PUA)
ComodoMalware@#jpcvqez9kb6r
BitDefenderThetaGen:NN.ZexaF.34142.umGfaGMYH2fG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Picsys.fc
FireEyeGeneric.mg.fc23de05f430e2a1
EmsisoftTrojan.Ransom.Kraken (A)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Gen.akq
AviraTR/DelFile.cjsfa
Antiy-AVLTrojan/Generic.ASMalwS.2A73129
MicrosoftTrojan:Win32/Occamy.C8F
ArcabitTrojan.Ursu.D5CF7F
GDataGen:Variant.Ursu.380799
AhnLab-V3Malware/Win32.Generic.C2984409
McAfeeArtemis!FC23DE05F430
VBA32BScope.TrojanRansom.Gen
PandaTrj/GdSda.A
YandexTrojan.GenAsa!gARIqwzv6bk
IkarusTrojan-Ransom.FileCrypter
FortinetW32/Gen.KWA!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ursu.380799?

Ursu.380799 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment