Malware

Ursu.523954 (file analysis)

Malware Removal

The Ursu.523954 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.523954 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Attempts to delete volume shadow copies
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

How to determine Ursu.523954?


File Info:

crc32: 12C045D0
md5: cfd417a62c519e3956a9cf6a64de9de0
name: CFD417A62C519E3956A9CF6A64DE9DE0.mlw
sha1: c640186277140724b30b8985d4cc7cfbc8954aaa
sha256: dfad35ba7b9bc3e98d500bb930f5f98f037c286eb9f53f0444434d11d9b403b2
sha512: a108c1d34f622d153223896c098d48b70e982fe3d9547da11596fe1d3e08154ff870313e5f5c1e8f0a0bc66c1f6d0e91a7f3c54eff4bb8fb6dc6a862b8ae6a6b
ssdeep: 12288:Axj8bdECHw7vDFqwJtOGZQJf6LiEBS6+d4:Axj8bdWHtOGKlEBH+d4
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Ursu.523954 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3953
McAfeeArtemis!CFD417A62C51
CylanceUnsafe
ZillyaTrojan.Crusis.Win32.1180
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/Crusis.f08d2826
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.EBWT
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 99)
KasperskyTrojan-Ransom.Win32.Crusis.cxm
BitDefenderGen:Variant.Ursu.523954
NANO-AntivirusTrojan.Win32.Encoder.fjxpxw
ViRobotTrojan.Win32.S.Agent.408064.CA
MicroWorld-eScanGen:Variant.Ursu.523954
TencentWin32.Trojan.Crusis.Tdzg
Ad-AwareGen:Variant.Ursu.523954
SophosML/PE-A
ComodoMalware@#1h1bqml3tbjqa
BitDefenderThetaAI:Packer.6314A36121
TrendMicroRansom_CRYSIS.F117A9
McAfee-GW-EditionBehavesLike.Win32.Ransomware.fc
FireEyeGeneric.mg.cfd417a62c519e39
EmsisoftGen:Variant.Ursu.523954 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Suspicious.Heur
AviraHEUR/AGEN.1100580
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.295BDF2
MicrosoftTrojan:Win32/Dynamer!rfn
ZoneAlarmTrojan-Ransom.Win32.Crusis.cxm
GDataGen:Variant.Ursu.523954
AhnLab-V3Malware/Win32.Ransom_crysis.C2858033
Acronissuspicious
VBA32BScope.TrojanSpy.Panda
MAXmalware (ai score=80)
MalwarebytesMalware.AI.1772693519
PandaTrj/CI.A
TrendMicro-HouseCallRansom_CRYSIS.F117A9
RisingTrojan.Generic@ML.100 (RDML:MZUTyEI39TeJltVkTxk9sA)
FortinetW32/GenKryptik.CQHQ!tr.ransom
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Ursu.523954?

Ursu.523954 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment