Malware

Ursu.622867 malicious file

Malware Removal

The Ursu.622867 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.622867 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image

How to determine Ursu.622867?


File Info:

crc32: A83026DA
md5: eef72f1182fd10124914ba82bcd1c006
name: EEF72F1182FD10124914BA82BCD1C006.mlw
sha1: 3ee0a4caade66b3a2dc11bfa76c5ae840c271582
sha256: 8fb24d9c4f2b2459abdb3947222cabfd7bc94089327a7258e49150016a0ee24d
sha512: 1e50acc0489b48c2737cfa552a51eb0671882e11157b6cdfc88ec82289082296199cf940e3e2edab3291f120702c51c52943c440a726dbd3eed4de20c7644ec0
ssdeep: 6144:YySsOIaULa9u1UDo2CrrrrrrrrOmkdBblcIP0haJz4eyQRdrCuLHYvgNN1iqoNp:zUDo2Crrrrrrrre0haJbyEjYv41joNp
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 9.9.9.9
InternalName: 6.exe
FileVersion: 9.7.9.7
ProductName: Windows
ProductVersion: 9.7.9.7
FileDescription: Windows
OriginalFilename: 6.exe

Ursu.622867 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.ClipBankerNET.5
CynetMalicious (score: 90)
ALYacGen:Variant.Ursu.622867
CylanceUnsafe
ZillyaTrojan.Banker.Win32.109422
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:MSIL/Banker.dd9d2462
K7GWTrojan ( 004ff6781 )
K7AntiVirusTrojan ( 004ff6781 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/ClipBanker.AC
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Spy.MSIL.Banker.asu
BitDefenderGen:Variant.Ursu.622867
NANO-AntivirusTrojan.Win32.Banker.epqglw
MicroWorld-eScanGen:Variant.Ursu.622867
TencentMsil.Trojan-spy.Banker.Aqgl
Ad-AwareGen:Variant.Ursu.622867
SophosMal/Generic-S
ComodoMalware@#1vy4psm3wihwg
F-SecureTrojan.TR/Dropper.MSIL.Gen
BitDefenderThetaGen:NN.ZemsilF.34608.uq0@ay0vCnh
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.USGD1017
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
FireEyeGeneric.mg.eef72f1182fd1012
EmsisoftGen:Variant.Ursu.622867 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.MSIL.Gen
eGambitUnsafe.AI_Score_94%
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Ursu.D98113
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmTrojan-Spy.MSIL.Banker.asu
GDataGen:Variant.Ursu.622867
AhnLab-V3Trojan/Win32.Banker.R200876
McAfeeArtemis!EEF72F1182FD
MAXmalware (ai score=84)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.USGD1017
RisingSpyware.Banker!8.8D (CLOUD)
YandexTrojan.ClipBanker!dnRbNAAHScs
IkarusTrojan.MSIL.ClipBanker
FortinetMSIL/Generic.DN.11CFE4!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/TrojanPSW.Generic.HwMA4PoA

How to remove Ursu.622867?

Ursu.622867 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment