Malware

How to remove “Ursu.709925”?

Malware Removal

The Ursu.709925 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Ursu.709925 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • A system process is generating network traffic likely as a result of process injection
  • Creates a copy of itself
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Ursu.709925?


File Info:

crc32: 65843880
md5: cdaa54c066151e2ba0212f019428eb43
name: fb10.txt
sha1: ad6b7a0f43a941798b7ca8e9318e4da2a478bdcf
sha256: 07d5f4036ad9e9a770fd890ebff70998a11353acf7c0a5d60be7498051eea8d5
sha512: 9a97fba63707cbfed4689ff957a892885d15e514d2b94252b60b2f153b11df5815076eddca9f4d52572b14bedf55dc771c6ba73f95f84c2af453bdec9a4e55af
ssdeep: 12288:9i9yCfd31z5UAhss5teN/WQD4F3yjLwYU7WOeBtYlkD6:DMlz5UAOsuwNijLTUKOeBClkD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ursu.709925 also known as:

MicroWorld-eScanGen:Variant.Ursu.709925
FireEyeGeneric.mg.cdaa54c066151e2b
McAfeeFareit-FQC!CDAA54C06615
MalwarebytesTrojan.MalPack.DLF
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Ursu.709925
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.f43a94
TrendMicroTrojanSpy.Win32.LOKI.SMAD1.hp
BitDefenderThetaGen:NN.ZelphiF.32253.1GX@aKbZG8hi
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SMAD1.hp
GDataGen:Variant.Ursu.709925
KasperskyHEUR:Trojan-Spy.Win32.Noon.gen
RisingTrojan.Generic@ML.100 (RDML:N9080rZPJeB0f4TRgmLx2A)
Ad-AwareGen:Variant.Ursu.709925
SophosMal/Fareit-V
DrWebTrojan.Fakealert.origin
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Fareit.ch
SentinelOneDFI – Suspicious PE
Trapminemalicious.high.ml.score
APEXMalicious
Endgamemalicious (high confidence)
ArcabitTrojan.Ursu.DAD525
ZoneAlarmHEUR:Trojan-Spy.Win32.Noon.gen
MicrosoftTrojan:Win32/Lokibot.CS!MTB
AhnLab-V3Win-Trojan/Delphiless.Exp
Acronissuspicious
ALYacGen:Variant.Ursu.709925
MAXmalware (ai score=88)
CylanceUnsafe
ESET-NOD32a variant of Win32/GenKryptik.DYKF
FortinetW32/Agent.AJFK!tr
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360HEUR/QVM05.1.6F5F.Malware.Gen

How to remove Ursu.709925?

Ursu.709925 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment