Malware

Ursu.445885 malicious file

Malware Removal

The Ursu.445885 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.445885 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

sdteam.no-ip.biz

How to determine Ursu.445885?


File Info:

crc32: 1C07198E
md5: 61f67882e45a14d514021dd7b614e350
name: 61F67882E45A14D514021DD7B614E350.mlw
sha1: 06f048cd360e9e03575b97f69a65512f815c26a6
sha256: 217e2f5b448500bf45c668c64f4bb0213159b8e50d6b77134da5d6e0cf560bb4
sha512: 8d399628438f6f2f8f0c583a4a98e1c7392f5d2dd89ef3efa3502f6a9a21962d72960f56c97481c761c0db5ae227bd29fe02f87202fe6e07c5f1ebcd550481f6
ssdeep: 12288:Dco9t7BwqNe2a882JdBZJ9IJypz+Q9Jm3wJIoVYIdR+17MWf0q7Dw:Dcof0Md3J9+KdJIoeIdU1oG08
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Ursu.445885 also known as:

K7AntiVirusTrojan ( 700000121 )
LionicTrojan.MSIL.Zapchast.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader12.45690
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.445885
CylanceUnsafe
ZillyaDropper.Agent.Win32.210488
SangforBackdoor.Win32.Bladabindi.1
K7GWTrojan ( 700000121 )
Cybereasonmalicious.2e45a1
BaiduMSIL.Backdoor.Bladabindi.a
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Bladabindi.AQ
APEXMalicious
AvastMSIL:GenMalicious-DNX [Trj]
ClamAVWin.Packed.Bladabindi-7086597-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.445885
NANO-AntivirusTrojan.Win32.Zapchast.dpgyls
MicroWorld-eScanGen:Variant.Ursu.445885
TencentMsil.Trojan.Zapchast.Wptm
Ad-AwareGen:Variant.Ursu.445885
SophosMal/Generic-S
ComodoMalware@#jl50g9t2vrkk
BitDefenderThetaGen:NN.ZemsilF.34294.orW@aWVHLjf
VIPREBackdoor.MSIL.Bladabindi.a (v)
McAfee-GW-EditionBackDoor-FDNN!61F67882E45A
FireEyeGeneric.mg.61f67882e45a14d5
EmsisoftGen:Variant.Ursu.445885 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1118346
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.EFC2D7
MicrosoftBackdoor:MSIL/Bladabindi.AJ
GDataGen:Variant.Ursu.445885
AhnLab-V3Trojan/Win32.Generic.C209723
McAfeeBackDoor-FDNN!61F67882E45A
MAXmalware (ai score=82)
VBA32Trojan.MSIL.Zapchast
PandaTrj/CI.A
RisingBackdoor.Njrat!1.9E49 (CLASSIC)
YandexTrojan.DR.Agent!bjhkQAp57IA
IkarusTrojan.MSIL.Zapchast
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.BJO!tr
AVGMSIL:GenMalicious-DNX [Trj]
Paloaltogeneric.ml

How to remove Ursu.445885?

Ursu.445885 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment