Malware

What is “Ursu.406858”?

Malware Removal

The Ursu.406858 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.406858 virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.406858?


File Info:

crc32: AE09E470
md5: 3fb07518c6bc246ce22f5073a987fed8
name: 3FB07518C6BC246CE22F5073A987FED8.mlw
sha1: 828ef42a35434bf7fd2812ff244e0c6fc343917c
sha256: e1ddf05e692541f644c368954838681caab5533d19722cd0e7d2f6e1a405911a
sha512: 3a92a9e859eed8acf2fbe51d9a522f34cbe3fd45c32f95b69e7e2130892b281322cd6909e562a273428a7ce8273044f98a2078538fb4fad7178d3fe17e543bb6
ssdeep: 6144:n8nf/zNYCy8gq4OVGrvKH4gWsubyJDoI:2qCyAVaiH4gKOE
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2021
Assembly Version: 1.0.0.0
InternalName: WindowsApplication12.exe
FileVersion: 1.0.0.0
ProductName: WindowsApplication12
ProductVersion: 1.0.0.0
FileDescription: WindowsApplication12
OriginalFilename: WindowsApplication12.exe

Ursu.406858 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.406858
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
Cybereasonmalicious.8c6bc2
CyrenW32/S-a3a977d3!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.KCH
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Packed.Hpbladabi-6860330-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.406858
MicroWorld-eScanGen:Variant.Ursu.406858
Ad-AwareGen:Variant.Ursu.406858
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34722.qq0@aOQ4THo
VIPRETrojan.Win32.Generic!BT
TrendMicroBKDR_HPBLADABI.SM2
McAfee-GW-EditionGenericRXNJ-VK!3FB07518C6BC
FireEyeGeneric.mg.3fb07518c6bc246c
EmsisoftGen:Variant.Ursu.406858 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1112891
MicrosoftProgram:Win32/Wacapew.C!ml
GridinsoftTrojan.Heur!.020130A1
GDataGen:Variant.Ursu.406858
AhnLab-V3Trojan/Win.Generic.C4504616
Acronissuspicious
McAfeeGenericRXNJ-VK!3FB07518C6BC
MAXmalware (ai score=85)
MalwarebytesTrojan.Crypt.MSIL.Generic
PandaTrj/CI.A
TrendMicro-HouseCallBKDR_HPBLADABI.SM2
IkarusPCK.MSIL
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.KCH!tr
AVGWin32:Trojan-gen

How to remove Ursu.406858?

Ursu.406858 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment