Malware

How to remove “Ursu.70788”?

Malware Removal

The Ursu.70788 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.70788 virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to stop active services
  • Anomalous binary characteristics

How to determine Ursu.70788?


File Info:

crc32: 761704EC
md5: 40329efac344b088ecd595d78803d0a0
name: 40329EFAC344B088ECD595D78803D0A0.mlw
sha1: c32da8ee869a7749e877eb5083c3de9bdf1376f3
sha256: 7b009c2b16bbb35326d64b2d905d61cadf09989f6d60cfdaf256d58ab400a639
sha512: 5e9a689de800a908c130c7df7dfc51b97d2e1feb1bfb1c3d85c118bf03b68d8a4d2bcba9c86fae891397c825715c71849efb1e4375bd5150fc393e92d0e28d9e
ssdeep: 24576:Y3L0ZLRlJrNhfRiz7ceYIjJALRB7V+tLusiAJCaqJSxl7+tLusiAJCaqJSxl:pf8ALR3Mus7CCNMus7CC
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Ursu.70788 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00503e681 )
DrWebTrojan.Encoder.10298
CynetMalicious (score: 100)
ALYacTrojan.Ransom.7Zipper
CylanceUnsafe
ZillyaTrojan.Deshacop.Win32.790
SangforVirus_Suspicious.Win32.Sality.ae
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojan:Win32/Deshacop.1b544f1d
K7GWTrojan ( 00503e681 )
Cybereasonmalicious.ac344b
ESET-NOD32a variant of Win32/Filecoder.XRatLocker.E
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Deshacop.emw
BitDefenderGen:Variant.Ursu.70788
NANO-AntivirusTrojan.Win32.Filecoder.eltczq
MicroWorld-eScanGen:Variant.Ursu.70788
TencentWin32.Trojan.Raas.Auto
Ad-AwareGen:Variant.Ursu.70788
SophosMal/Generic-S
ComodoTrojWare.Win32.Ransom.XRatLocker.D@7b6770
BitDefenderThetaGen:NN.ZexaF.34608.YLW@a0bAwzh
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_XRAT.F117C9
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.40329efac344b088
EmsisoftGen:Variant.Ursu.70788 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/ATRAPS.Gen
KingsoftWin32.Troj.Deshacop.e.(kcloud)
MicrosoftTrojan:Win32/Skeeyah.A!rfn
ArcabitTrojan.Ursu.D11484
AegisLabTrojan.Win32.Generic.4!c
GDataWin32.Trojan-Ransom.Zipper.A
AhnLab-V3Trojan/Win32.Deshacop.C1849047
McAfeeArtemis!40329EFAC344
MAXmalware (ai score=99)
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/CI.A
TrendMicro-HouseCallRansom_XRAT.F117C9
RisingRansom.FileCryptor!8.1A7 (CLOUD)
IkarusTrojan-Ransom.Xratlocker
FortinetW32/Generic.AC.3D3CED!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.78d

How to remove Ursu.70788?

Ursu.70788 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment