Malware

What is “Ursu.382944”?

Malware Removal

The Ursu.382944 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.382944 virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.382944?


File Info:

crc32: B077C65C
md5: 28d099d357bb1f1332d99dd249bbf17c
name: 28D099D357BB1F1332D99DD249BBF17C.mlw
sha1: 990ac6a1ff99fadb6788900c38775e343d7203ed
sha256: 07afb857de813419c8353fc549ba8a5d9616771e56dcdf9921878d5ac87a780b
sha512: ab2c77a7b5233c346063d0e9886e1a5655a38fbf0c96eb25ab24cbc9bebe12b4cb5bd38d478fe71abcfea081632631285514b845828766537bea873e5e81d884
ssdeep: 6144:f/+EPEwTF8ya8wSOX0QW+CYnGLR/YjHl1lRKC3tsMztZa:f/PEwTF8ywCYnGLR/Yj0MzLa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ursu.382944 also known as:

MicroWorld-eScanGen:Variant.Ursu.382944
FireEyeGeneric.mg.28d099d357bb1f13
McAfeeGenericRXCK-HF!28D099D357BB
CylanceUnsafe
VIPRETrojan.FakeAlert
SangforTrojan.Win32.Save.a
BitDefenderGen:Variant.Ursu.382944
Cybereasonmalicious.357bb1
CyrenW32/FakeAlert.TD.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/LockScreen.3b07d627
NANO-AntivirusTrojan.Win32.TrjGen.cwxadt
AegisLabTrojan.Win32.Skillis.lqzG
TencentWin32.Trojan.Lockscreen.Htwa
Ad-AwareGen:Variant.Ursu.382944
EmsisoftGen:Variant.Ursu.382944 (B)
ComodoMalware@#2qf1dc91510qo
F-SecureHeuristic.HEUR/AGEN.1130405
DrWebTrojan.Siggen4.27770
McAfee-GW-EditionGenericRXCK-HF!28D099D357BB
SophosMal/Generic-S
IkarusTrojan.Win32.Mepaow
JiangminTrojan/Skillis.dhi
MaxSecureTrojan.Malware.121218.susgen
AviraHEUR/AGEN.1130405
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/GandCrypt.PVB!MTB
ArcabitTrojan.Ursu.D5D7E0
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Ursu.382944
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Skillis.R70856
BitDefenderThetaGen:NN.ZexaF.34590.nuW@aefKXcci
ALYacGen:Variant.Ursu.382944
MAXmalware (ai score=80)
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
ESET-NOD32a variant of Win32/LockScreen.APZ
RisingTrojan.LockScreen!8.1AF (CLOUD)
YandexTrojan.GenAsa!KmJ7m00AYjQ
SentinelOneStatic AI – Suspicious PE
FortinetW32/Skillis.OSH!tr
WebrootW32.Malware.Gen
AVGWin32:Trojan-gen
Qihoo-360Win32/Trojan.Generic.HwUB8zgA

How to remove Ursu.382944?

Ursu.382944 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment