Malware

Ursu.801126 (file analysis)

Malware Removal

The Ursu.801126 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.801126 virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ursu.801126?


File Info:

crc32: D70E7697
md5: 4ee8325f93b8d5d875decc5135058e1c
name: 4EE8325F93B8D5D875DECC5135058E1C.mlw
sha1: 87776a25b6e08357e393b6cfbadc5c2efc6bbbf5
sha256: d2b59a7b3465666f3aa6358411651ba44267bf59f7543cb4f62b14dde46ac778
sha512: 1f5bcd02ea4f7771ba7929c8dbb2c36d07f928ecbaf969ba0f54f340f93bc38faec9e794387b5f615ca28494ced9b6b1ad7fedfeaa2d5fbaa3645a6204f1087e
ssdeep: 384:SfkaoZ1zTF/YVAucIPNk4kGDUyE0psX1ZraLk24jXPl8uov/4Y5ym+R2DrWG:ZaIn/EAucIVRkGDUyE0mFA2XPI
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft 2020
Assembly Version: 1.0.0.0
InternalName: WindowsApplication60.exe
FileVersion: 1.0.0.0
CompanyName: Microsoft
ProductName: WindowsApplication60
ProductVersion: 1.0.0.0
FileDescription: WindowsApplication60
OriginalFilename: WindowsApplication60.exe

Ursu.801126 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.801126
FireEyeGeneric.mg.4ee8325f93b8d5d8
Qihoo-360Generic/Trojan.Downloader.979
ALYacGen:Variant.Ursu.801126
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan-Downloader ( 004c41161 )
BitDefenderGen:Variant.Ursu.801126
K7GWTrojan-Downloader ( 004c41161 )
Cybereasonmalicious.f93b8d
BitDefenderThetaGen:NN.ZemsilF.34804.bq0@aOigb8j
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Tiny.BB
APEXMalicious
AvastWin32:Trojan-gen
KasperskyHEUR:Trojan-Downloader.MSIL.Snoload.gen
AlibabaTrojanDownloader:MSIL/Snoload.6fcff039
NANO-AntivirusTrojan.Win32.Snoload.idumkk
Ad-AwareGen:Variant.Ursu.801126
SophosMal/Generic-S
ComodoMalware@#j22rjc8wlbfg
F-SecureHeuristic.HEUR/AGEN.1130638
ZillyaDownloader.Tiny.Win32.18700
TrendMicroTROJ_GEN.R014C0PL720
McAfee-GW-EditionGenericRXLP-CE!4EE8325F93B8
EmsisoftGen:Variant.Ursu.801126 (B)
IkarusTrojan-Downloader.MSIL.Tiny
JiangminTrojanDropper.MSIL.ayck
AviraHEUR/AGEN.1130638
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.Ursu.DC3966
ZoneAlarmHEUR:Trojan-Downloader.MSIL.Snoload.gen
GDataGen:Variant.Ursu.801126
CynetMalicious (score: 85)
McAfeeGenericRXLP-CE!4EE8325F93B8
MAXmalware (ai score=84)
VBA32TScope.Trojan.MSIL
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R014C0PL720
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Tiny.LG!tr.dldr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Ursu.801126?

Ursu.801126 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment