Malware

Should I remove “Ursu.601985”?

Malware Removal

The Ursu.601985 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.601985 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Ursu.601985?


File Info:

name: 1834192A9F093C4D6E7E.mlw
path: /opt/CAPEv2/storage/binaries/0e7f18cf964fe74d697d53fc1529461d58d4fc3a01ef783d613bf7f9a1ef1191
crc32: B71D868C
md5: 1834192a9f093c4d6e7ed9cef7426cc3
sha1: e9f12f9476d577fa351ad42ebb16ff94485f60c8
sha256: 0e7f18cf964fe74d697d53fc1529461d58d4fc3a01ef783d613bf7f9a1ef1191
sha512: a8b0d05484153d45ca86bf586ccf2006d95fc7843d21ab984a3e587d73c39715eabe0ccfd81307709a26e362ca96f8834c08b20385811323feb3522367319d92
ssdeep: 384:8seqKLVlmj0OYfIkR4whu2AJOQcA8sVRNI/MvwnwIyhio3iAG2qAuxYEKn:qvvL3s7royLNG2TEY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17A932B3D2AAC3123C970D2A3EF84CB56F1A19977B1D70CB96ED34F520512812BEC266D
sha3_384: 44848673a4c0711564c4cceaa213b43b77b8a87f6f73d0475b705b4a01ef304988bbf1ce34f6681fd297352920defe79
ep_bytes: ff2500204000
timestamp: 2018-05-01 13:29:52

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: dllhost
FileVersion: 1.0.0.0
InternalName: dllhost.exe
LegalCopyright: Copyright © 2018
LegalTrademarks:
OriginalFilename: dllhost.exe
ProductName: dllhost
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Ursu.601985 also known as:

LionicTrojan.MSIL.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.601985
FireEyeGeneric.mg.1834192a9f093c4d
McAfeeArtemis!1834192A9F09
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.MSIL.Injector.SBJ
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Injector.f7366d6c
K7GWTrojan ( 0050c5461 )
K7AntiVirusTrojan ( 0050c5461 )
BitDefenderThetaGen:NN.ZemsilF.34294.fm0@a8JrV4e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.SBJ
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Generic
BitDefenderGen:Variant.Ursu.601985
NANO-AntivirusTrojan.Win32.Zusy.fdgohk
AvastWin32:TrojanX-gen [Trj]
TencentMsil.Trojan.Generic.Dxdc
Ad-AwareGen:Variant.Ursu.601985
EmsisoftGen:Variant.Ursu.601985 (B)
ComodoMalware@#16n9lh0enex9r
ZillyaTrojan.Injector.Win32.892299
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-R + Troj/MSIL-JQG
IkarusTrojan.MSIL.Injector
GDataGen:Variant.Ursu.601985
JiangminTrojan.MSIL.lfkz
AviraHEUR/AGEN.1128542
MAXmalware (ai score=98)
Antiy-AVLTrojan/Generic.ASMalwS.2661E36
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Bladabindi!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.RL_Crypt.C3468374
VBA32TScope.Trojan.MSIL
ALYacGen:Variant.Ursu.601985
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Kryptik.WFI!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.a9f093
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.11196064.susgen

How to remove Ursu.601985?

Ursu.601985 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment