Malware

How to remove “Ursu.410380”?

Malware Removal

The Ursu.410380 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.410380 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Ursu.410380?


File Info:

crc32: 30BA8AA7
md5: c7eca77f3036867fe2baf16226dd70f0
name: C7ECA77F3036867FE2BAF16226DD70F0.mlw
sha1: ac3d3bfcb5480dce22b50c8a41a04c9ae5559320
sha256: ab4f5473a2b02df3ff4d4bcfad871fb22db4d356d474b940ec2592e5bef38eb2
sha512: 205bb7d3521e30f56aff6ad438e65e7f04dfa718331b7ed5e6774779225aa4867a23b0c0e41c3c0126b8f51463284812e98e4356a26214aa35a521d9ba301c53
ssdeep: 12288:PBOV3j6qj9KoFBElzbd4XA2aa4sqNiCrKO2JrEVO9z:pqjt0wBExx4XlaavqooV8
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2015
Assembly Version: 1.0.0.0
InternalName: MarvelPuzzleQuest_CH.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Cheathappens.com
ProductVersion: 1.0.0.0
FileDescription: Cheathappens.com
OriginalFilename: MarvelPuzzleQuest_CH.exe

Ursu.410380 also known as:

K7AntiVirusUnwanted-Program ( 0050f5081 )
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.Ursu.410380
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.39549
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/Blocker.2b58968b
K7GWUnwanted-Program ( 0050f5081 )
Cybereasonmalicious.f30368
CyrenW32/MSIL_Perseus.K.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Packed.Confuser.AW
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Gamehack-6828738-0
KasperskyTrojan-Ransom.Win32.Blocker.kqdr
BitDefenderGen:Variant.Ursu.410380
NANO-AntivirusTrojan.Win32.Blocker.exahzr
MicroWorld-eScanGen:Variant.Ursu.410380
Ad-AwareGen:Variant.Ursu.410380
SophosCheathappens (PUA)
BitDefenderThetaGen:NN.ZemsilF.34738.Rm0@aqSqWPg
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.c7eca77f3036867f
EmsisoftGen:Variant.Ursu.410380 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.idb
WebrootW32.Trojan.Gen
AviraTR/Blocker.fkiqo
Antiy-AVLTrojan/Generic.ASMalwS.2404F28
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.Ursu.D6430C
AegisLabTrojan.Win32.Blocker.j!c
GDataGen:Variant.Ursu.410380
AhnLab-V3Trojan/Win32.Agent.C3323182
McAfeeArtemis!C7ECA77F3036
MAXmalware (ai score=95)
VBA32Trojan-Ransom.Blocker
MalwarebytesHackTool.GameHack
PandaTrj/GdSda.A
YandexTrojan.Blocker!ndhiaihBuu8
IkarusTrojan.MSIL.Confuser
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Blocker.KQDR!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ursu.410380?

Ursu.410380 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment