Malware

Ursu.454359 removal guide

Malware Removal

The Ursu.454359 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.454359 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ursu.454359?


File Info:

crc32: 1739D72B
md5: 94a6a6621d29c6fe04da510e750e5849
name: Yulgang-Launcher-V18.exe
sha1: 998806f8a5f9ae3236a86d4b73f40cec0dba3a40
sha256: a23042cb49f699ae0bf6c286d00b1fa6ccc4fa7d0401a46a6aeaa3f2930a02ae
sha512: 9faf9eac10be4211959127f9af712786f3793bc12704de57303f58a4b1ded97858a9cd029c96bf3032c1a0311a02d83029d12dde6deb1042925e20cd54550ea6
ssdeep: 98304:NIVFg418eLk9kR8bf9sxUmUzmMCQvSzDskVcbSMgYW024mlEuS7+g8UEu4Nm9r2x:SVFgHs8f9kSa/s9gYL2/uUNAMf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) 2018
InternalName: Logon
FileVersion: 1, 0, 0, 0
ProductName: Logon
ProductVersion: 1, 0, 0, 0
FileDescription: Logon
OriginalFilename: Logon.EXE
Translation: 0x0804 0x04b0

Ursu.454359 also known as:

BkavHW32.Packed.
MicroWorld-eScanGen:Variant.Ursu.454359
FireEyeGeneric.mg.94a6a6621d29c6fe
Qihoo-360HEUR/QVM19.1.291F.Malware.Gen
CylanceUnsafe
BitDefenderGen:Variant.Ursu.454359
Cybereasonmalicious.21d29c
Invinceaheuristic
F-ProtW32/Downloader.I.gen!Eldorado
APEXMalicious
AvastWin32:Malware-gen
GDataGen:Variant.Ursu.454359
RisingTrojan.Generic!8.C3 (TFE:dGZlOgVd2ofQeWhZXg)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Ursu.454359 (B)
Trapminesuspicious.low.ml.score
IkarusVirus.Win32.Heur
CyrenW32/Downloader.I.gen!Eldorado
MAXmalware (ai score=86)
ArcabitTrojan.Ursu.D6EED7
MicrosoftTrojan:Win32/Wacatac.D!ml
AhnLab-V3Malware/Win32.Generic.C2624062
Acronissuspicious
ALYacGen:Variant.Ursu.454359
Ad-AwareGen:Variant.Ursu.454359
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_99%
BitDefenderThetaGen:NN.ZexaF.34090.@F1@aia!I2gj
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_80% (D)

How to remove Ursu.454359?

Ursu.454359 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment