Malware

Ursu.5256 removal

Malware Removal

The Ursu.5256 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.5256 virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ursu.5256?


File Info:

crc32: F19CF181
md5: dd7b114e8cebc76ec41742bb99f165f6
name: DD7B114E8CEBC76EC41742BB99F165F6.mlw
sha1: eab5e1289a771ef4dbb6c0c0349ab02f0d6080bb
sha256: 6de68365f8c830b13a49ea7af38ccc541c6d81777d2fe9130ab4b0a4077e2f4d
sha512: 6a57368c6314ec2651367e3e01f7892691b97762dfdb3046180121ec9a78a9b5e5d9ea436fee60945e7c14aeb0e9abfb87c2e39da5abd9c23fa55b9bff0a595d
ssdeep: 192:bLYoQ6rV6rQzYiocyWKsuZUaiI5SESkrYVE1UEJeTbL:H3Q6rV6rMqTFUaisSEbrYIi
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: PaidRobuxGenerator.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: PaidRobuxGenerator.exe

Ursu.5256 also known as:

K7AntiVirusTrojan ( 700000121 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.StealerNET.37
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.5256
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 700000121 )
Cybereasonmalicious.e8cebc
CyrenW32/Razy.CK.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/PSW.OnLineGames.BAT
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Packed.Razy-9793234-0
KasperskyHEUR:Trojan-GameThief.MSIL.Agent.gen
BitDefenderGen:Variant.Ursu.5256
NANO-AntivirusTrojan.Win32.OnLineGames.eovftk
MicroWorld-eScanGen:Variant.Ursu.5256
Ad-AwareGen:Variant.Ursu.5256
SophosML/PE-A
ComodoTrojWare.MSIL.Gendwndrop.BAT@7lxgqp
BitDefenderThetaGen:NN.ZemsilF.34758.am0@ayRZkbi
McAfee-GW-EditionGenericRXBX-TR!DD7B114E8CEB
FireEyeGeneric.mg.dd7b114e8cebc76e
EmsisoftGen:Variant.Ursu.5256 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.MSIL.bljs
AviraHEUR/AGEN.1101064
MicrosoftTrojanDropper:MSIL/Gendwndrop.M!bit
ArcabitTrojan.Ursu.D1488
GDataGen:Variant.Ursu.5256
AhnLab-V3Trojan/Win32.Gendwndrop.R361319
McAfeeGenericRXBX-TR!DD7B114E8CEB
MAXmalware (ai score=85)
MalwarebytesGeneric.Worm.Autorun.DDS
RisingStealer.OnLineGames/MSIL!1.D647 (CLASSIC)
IkarusTrojan.MSIL.PSW
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Onlinegames.BDN!tr.pws
AVGWin32:Trojan-gen

How to remove Ursu.5256?

Ursu.5256 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment