Malware

How to remove “Ursu.796559”?

Malware Removal

The Ursu.796559 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.796559 virus can do?

  • Unconventionial binary language: Urdu (Pakistan)
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Ursu.796559?


File Info:

crc32: 85528A6A
md5: 09c4d7662187742501fff209dfb37aac
name: 09C4D7662187742501FFF209DFB37AAC.mlw
sha1: bddece90eafa4de5e8acb7c4ec784cc967eadc9c
sha256: 7b8c61811738c433021935a58dd93946253bf1c63552841513a4699222ca2174
sha512: ae172a7954f58a049372f99c20d09c5909678c41bda3a8d6c8fdf454d8ca4ac000b8168acba6cfeacaeca00ce90226b8633c890cdce29943c507831c61ebd543
ssdeep: 98304:E2cPK8IvRP/F5BZZYvcyrGNuOkmpzrzQUgEI19XPziMSKGOchQOYgIYqM/79L:fCKX/FnZZVuGNpkmpzrzQPrzslOchMC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: ADMIN@CRACK
InternalName: Calculator
FileVersion: 1.0.0.0
CompanyName: URET
LegalTrademarks: Team URET
ProductName: Calculator
ProductVersion: 1.0.0.0
FileDescription: Bugs remover ;)
OriginalFilename: Calc.exe
Translation: 0x0420 0x0000

Ursu.796559 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader34.30390
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Agent
ALYacTrojan.GenericKD.40508646
CrowdStrikewin/malicious_confidence_80% (W)
Cybereasonmalicious.621877
CyrenW32/AutoIt.RN.gen!Eldorado
ESET-NOD32multiple detections
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Spy.MSIL.Quasar.kcg
BitDefenderGen:Variant.Ursu.796559
NANO-AntivirusRiskware.Win32.Miner.hplahx
MicroWorld-eScanGen:Variant.Ursu.796559
Ad-AwareGen:Variant.Ursu.796559
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34236.5z0aaGzcwiec
TrendMicroTROJ_GEN.R002C0PG321
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.tc
FireEyeGeneric.mg.09c4d76621877425
EmsisoftGen:Variant.Ursu.796559 (B)
AviraTR/Crypt.TPM.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.30B8FCF
MicrosoftPUA:Win32/Keygen
GDataMSIL.Backdoor.Quasar.II95HA
McAfeeArtemis!09C4D7662187
MAXmalware (ai score=81)
TrendMicro-HouseCallTROJ_GEN.R002C0PG321
RisingTrojan.Generic@ML.100 (RDML:Zen44fHIssPlb7d58ZrTfw)
IkarusTrojan.Win32.Themida
FortinetRiskware/Miner
AVGWin32:Malware-gen

How to remove Ursu.796559?

Ursu.796559 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment