Malware

Ursu.389309 removal

Malware Removal

The Ursu.389309 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.389309 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to restart the guest VM
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Network activity detected but not expressed in API logs

Related domains:

edgedl.me.gvt1.com
update.googleapis.com

How to determine Ursu.389309?


File Info:

crc32: CE11B9E9
md5: 92548d2904158c0e9e93b2310c494816
name: 92548D2904158C0E9E93B2310C494816.mlw
sha1: ab1dd824ae04cdb82fccb2a66600099d34ea8541
sha256: 352c3b7c7f30ea19abf12d58c69606b866b4645e7a2999d5434cd122fb73f1f0
sha512: 260f82ebf30ad843afb4d72b87c54227603f8ed3f58990ac611e6082512fed55ecf2dd500d5ce27aca74153ed276131fe29bd14a942a40fe7df4e310b9aa8190
ssdeep: 12288:5H2J0YJ7zNOxntF/QRWY4hYfa7TJqFxjDKopA1TWgT:N2mYJFATYRWYpfmtqFNDZU
type: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed

Version Info:

0: [No Data]

Ursu.389309 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen8.5408
ALYacGen:Variant.Ursu.389309
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win32/Pitou.ca359836
K7GWTrojan ( 0051ac701 )
K7AntiVirusTrojan ( 0051ac701 )
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Pitou.K
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.389309
NANO-AntivirusTrojan.Win32.Pitou.fnsbxl
MicroWorld-eScanGen:Variant.Ursu.389309
TencentWin32.Trojan.Generic.Hreq
Ad-AwareGen:Variant.Ursu.389309
SophosMal/Generic-S
ComodoMalware@#g8powf0gu6in
BitDefenderThetaGen:NN.ZexaF.34170.LmWfaGTbqmd
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.92548d2904158c0e
EmsisoftGen:Variant.Ursu.389309 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agent.bucd
AviraHEUR/AGEN.1137954
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2AB6972
MicrosoftTrojan:Win32/Occamy.C35
GDataGen:Variant.Ursu.389309
AhnLab-V3Malware/Win32.Generic.C3087557
McAfeeArtemis!92548D290415
MAXmalware (ai score=83)
VBA32Trojan.Tiggre
PandaTrj/CI.A
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
IkarusTrojan.Win32.Pitou
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/GandCrab_V5_2!tr.ransom
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Ursu.389309?

Ursu.389309 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment