Malware

Ursu.437965 (B) (file analysis)

Malware Removal

The Ursu.437965 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.437965 (B) virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ursu.437965 (B)?


File Info:

crc32: AAB9978E
md5: f3089e4bf30f3dc37289271f7e6214a4
name: F3089E4BF30F3DC37289271F7E6214A4.mlw
sha1: e8eae28c1e426e313f045b6d218521392b515c25
sha256: 9a4ef93705f5d81623e327511b31b1a3e79993cacc1ad84b20addb7ba2c38522
sha512: 72102ba8ac909d57e791014b24b5bf419a73ec5774fb8356f07c97bf35d3e1503131ae7bc1d34188c38def7a3b3f54a7f39176077b36432a3664db8d1418d041
ssdeep: 192:PY1pefHTojtCglm7NrYq5R519eSnGSc7ApbKcg9bESAs:P2pefzojtCglmFYqL5feS8N9QSA
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2021
Assembly Version: 1.0.0.0
InternalName: Stealer.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Stealer
ProductVersion: 1.0.0.0
FileDescription: Stealer
OriginalFilename: Stealer.exe

Ursu.437965 (B) also known as:

Elasticmalicious (high confidence)
DrWebTrojan.ClipBankerNET.22
CynetMalicious (score: 99)
ALYacGen:Variant.Ursu.437965
AlibabaTrojanBanker:MSIL/ClipBanker.e2c11c94
Cybereasonmalicious.bf30f3
CyrenW32/MSIL_Troj.AAW.gen!Eldorado
ESET-NOD32a variant of MSIL/ClipBanker.PW
APEXMalicious
AvastWin32:PWSX-gen [Trj]
KasperskyHEUR:Trojan-Banker.MSIL.ClipBanker.gen
BitDefenderGen:Variant.Ursu.437965
MicroWorld-eScanGen:Variant.Ursu.437965
Ad-AwareGen:Variant.Ursu.437965
BitDefenderThetaGen:NN.ZemsilF.34722.am0@aaf5tOo
FireEyeGeneric.mg.f3089e4bf30f3dc3
EmsisoftGen:Variant.Ursu.437965 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1137599
MicrosoftTrojan:MSIL/ClipBanker.GA!MTB
ArcabitTrojan.Ursu.D6AECD
ZoneAlarmHEUR:Trojan-Banker.MSIL.ClipBanker.gen
GDataGen:Variant.Ursu.437965
AhnLab-V3Malware/Win.Generic.C4475795
MAXmalware (ai score=84)
MalwarebytesSpyware.PasswordStealer.MSIL
RisingSpyware.ClipBanker!1.D05B (CLASSIC)
IkarusTrojan.MSIL.ClipBanker
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/ClipBanker.PW!tr
AVGWin32:PWSX-gen [Trj]

How to remove Ursu.437965 (B)?

Ursu.437965 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment