Malware

About “Ursu.728548” infection

Malware Removal

The Ursu.728548 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.728548 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Anomalous binary characteristics

How to determine Ursu.728548?


File Info:

crc32: F53E435D
md5: 93185dbdeba8ddee862654e176ab7a15
name: 93185DBDEBA8DDEE862654E176AB7A15.mlw
sha1: 56cb27b3d31a56b18c24c9785667bd727b825aaf
sha256: 5a43ae9700e9d014567ad1a6cba58e11e6957b7053572a0a80e2f0487597da64
sha512: 38c80c56edc53908dfd766b73aff283d68efffcfc3ceb7fc87766d25bb8494112be0d18fa0aeecfb2e88fa1200c8f102076fb3b35b52c96dfef8944ccc603135
ssdeep: 384:M0IRltHJLo4kPIJUaFQR9i5EHOrabDufnwWZ7JLk24jXPlH1CGa3XgQEX3Dh53p:M0IztH1GVvi5eOAcfT2XPDnjHRW
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2010
Assembly Version: 1.0.0.0
InternalName: D.exe
FileVersion: 1.0.0.0
ProductName: WindowsApplication1
ProductVersion: 1.0.0.0
FileDescription: WindowsApplication1
OriginalFilename: D.exe

Ursu.728548 also known as:

K7AntiVirusTrojan ( 00504e2d1 )
CynetMalicious (score: 85)
ALYacGen:Variant.Ursu.728548
CylanceUnsafe
ZillyaTrojan.Agent.Win32.778485
SangforRansom.MSIL.Tpyn.chu
AlibabaTrojan:MSIL/Filecoder.48467ffb
K7GWTrojan ( 00504e2d1 )
Cybereasonmalicious.deba8d
ESET-NOD32a variant of MSIL/Filecoder.Harzhuangzi.A
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Ransom.MSIL.Tpyn.chu
BitDefenderGen:Variant.Ursu.728548
NANO-AntivirusTrojan.Win32.FileCoder.emwdcb
MicroWorld-eScanGen:Variant.Ursu.728548
TencentMsil.Trojan.Tpyn.Hqbg
SophosMal/Generic-S
ComodoMalware@#1w5fjnrmhsh6z
BitDefenderThetaGen:NN.ZemsilF.34628.bq0@aKNUHkm
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_STUPZHUANGZI.SM
EmsisoftGen:Variant.Ursu.728548 (B)
WebrootW32.Ransom.Gen
AviraTR/FileCoder.npjgw
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ArcabitTrojan.Ursu.DB1DE4
AegisLabTrojan.MSIL.Tpyn.j!c
ZoneAlarmHEUR:Trojan-Ransom.MSIL.Tpyn.chu
GDataMSIL.Trojan-Ransom.Filecoder.AU
AhnLab-V3Trojan/Win32.FileCryptor.C1954352
McAfeeArtemis!93185DBDEBA8
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
RisingRansom.FileCryptor!8.1A7 (CLOUD)
YandexTrojan.Filecoder!osD1wIePSQ4
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Filecoder.FG!tr.ransom
AVGWin32:Malware-gen
Qihoo-360Win32/Ransom.Filecoder.HgIASRIA

How to remove Ursu.728548?

Ursu.728548 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment