Malware

Should I remove “Ursu.61035”?

Malware Removal

The Ursu.61035 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.61035 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ursu.61035?


File Info:

crc32: 241DBB11
md5: 133e292bf34ced0f4c617f6828e58ebb
name: 133E292BF34CED0F4C617F6828E58EBB.mlw
sha1: acadd90b66325f9ad2e887b8861e53d20f15631a
sha256: 8be6d151f8103ba3f24c6f457588f174da679613a084998c494091c1474d5a77
sha512: 3039b914ffeece8eff0c46d98f9a90517df2b959b3e0596dbb537b4c2afac5f069992072c9a80b133cc49098133136676ee6985b55f30c01ffd0232dc8f9fa49
ssdeep: 12288:7fGm9yShnDxhVna42/niN3UFtvBOyRISIFkS:yIyanDx/na4CnPbBOyD3S
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Delphi Automotive (C) 2007-2015
FileVersion: 9.2.7.5
CompanyName: Delphi Automotive
LegalTrademarks: Delphi Automotive (C) 2007-2015
Comments: Thoughts 929395 Vdt Handoffs Acres Studentos
ProductName: Boss
ProductVersion: 9.2.7.5
FileDescription: Thoughts 929395 Vdt Handoffs Acres Studentos
Translation: 0x0409 0x04b0

Ursu.61035 also known as:

BkavW32.Common.E6BFCA32
K7AntiVirusTrojan ( 005216281 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Ransom.BTCWare
CylanceUnsafe
ZillyaTrojan.Gen.Win32.1615
SangforRansom.Win32.Gen.gib
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/GandCrab.75f2b0f8
K7GWTrojan ( 005216281 )
Cybereasonmalicious.bf34ce
SymantecRansom.BTCware
ESET-NOD32a variant of Generik.MFRFJIA
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Gen.gib
BitDefenderGen:Variant.Ursu.61035
NANO-AntivirusTrojan.Win32.Mlw.ewgjli
MicroWorld-eScanGen:Variant.Ursu.61035
TencentWin32.Trojan.Gen.Dvgg
Ad-AwareGen:Variant.Ursu.61035
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34670.yu0@a4lJrigi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.BadFile.fc
FireEyeGeneric.mg.133e292bf34ced0f
EmsisoftGen:Variant.Ursu.61035 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1108024
eGambitUnsafe.AI_Score_95%
MicrosoftRansom:Win32/Betisrypt.D
ArcabitTrojan.Ursu.DEE6B
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Ursu.61035
AhnLab-V3Trojan/Win32.Crypt.C2311452
Acronissuspicious
McAfeeArtemis!133E292BF34C
MAXmalware (ai score=94)
VBA32BScope.Trojan.Azden
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/CI.A
RisingRansom.Gen!8.DE83 (CLOUD)
IkarusTrojan-Ransom.GandCrab
FortinetGenerik.MFRFJIA!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Generic.HwoCnZ0A

How to remove Ursu.61035?

Ursu.61035 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment