Malware

Ursu.576438 removal instruction

Malware Removal

The Ursu.576438 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.576438 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • Exhibits possible ransomware file modification behavior
  • Network activity detected but not expressed in API logs
  • Likely virus infection of existing system binary
  • Anomalous binary characteristics

How to determine Ursu.576438?


File Info:

crc32: 0BDE6FFF
md5: 9f851941f5b933386ceb612a12a68ac9
name: 9F851941F5B933386CEB612A12A68AC9.mlw
sha1: 2a47d0cb3f66078e7d0ab0c8f10ceaf9bbe6811c
sha256: 4c103a3aef203a6e2cc7d42f25aab0f17bf56989dae111f89b9addef1f3dcdfe
sha512: 7e10b2744339611da09d26f153701e555239d199f797a6fc97eb38c82f771fe2df129ad76d31744f3a8b33799fc0cde316ae65e4cf3b167c7fd21de9d71a50bf
ssdeep: 12288:hvS+Y0ijTXtIFLSGgONBdIPZspDLg/sXD2:N+TXq5SbYDIhsOMa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 Donald Kackman
InternalName: Cool Clock Screen Saver
FileVersion: 1.1
CompanyName: IT Software Engineering, Inc.
Comments: Written by Don Kackman
ProductName: Cool Clock Screen Saver
ProductVersion: 1.1
FileDescription: Cool Clock Screen Saver
OriginalFilename: ClockSaver.scr
Translation: 0x0409 0x04b0

Ursu.576438 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.576438
FireEyeGeneric.mg.9f851941f5b93338
ALYacGen:Variant.Ursu.576438
AegisLabTrojan.Win32.Ursu.4!c
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Ursu.576438
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.1f5b93
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Ransom.Win32.Cryptor.cpx
AlibabaRansom:Win32/Cryptor.b3ab8f13
NANO-AntivirusTrojan.Win32.Azorult.gakllk
RisingTrojan.Casur!8.10E51 (CLOUD)
Ad-AwareGen:Variant.Ursu.576438
EmsisoftGen:Variant.Ursu.576438 (B)
F-SecureTrojan.TR/Strictor.suecb
ZillyaTrojan.Kryptik.Win32.1713176
TrendMicroRansom.Win32.RYUK.HTW
McAfee-GW-EditionArtemis
SophosMal/Generic-S
JiangminTrojan.PSW.Predator.nk
AviraTR/Strictor.suecb
MAXmalware (ai score=81)
MicrosoftTrojan:Win32/Predator.GJ!MTB
ArcabitTrojan.Ursu.D8CBB6
ZoneAlarmTrojan-Ransom.Win32.Cryptor.cpx
GDataGen:Variant.Ursu.576438
CynetMalicious (score: 85)
McAfeeArtemis!9F851941F5B9
VBA32BScope.TrojanPSW.Azorult
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.GWHK
TrendMicro-HouseCallRansom.Win32.RYUK.HTW
TencentMalware.Win32.Gencirc.11695378
FortinetW32/Kryptik.GWHK!tr.ransom
BitDefenderThetaGen:NN.ZexaF.34590.Uu0@aiLn5Dei
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (D)
Qihoo-360Win32/Ransom.Cryptor.HwoCPBkA

How to remove Ursu.576438?

Ursu.576438 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment