Malware

Ursu.82237 removal guide

Malware Removal

The Ursu.82237 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.82237 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.

How to determine Ursu.82237?


File Info:

crc32: D30AB6E3
md5: ed3de6ffdad8e3cbc48c494f1e65d32b
name: ED3DE6FFDAD8E3CBC48C494F1E65D32B.mlw
sha1: 74aec6342f9e3cc50533124683b293b5da3014f3
sha256: 5fc981e990387ef18a32a5b8396aea2ffc37f31f1a8f5a95ca9c583bde9b5667
sha512: ac2523e4310daaeebbed5d37e32993ed45f72c0eb3d398734a7907e0137b9e1b49676c63d37efbf6468def78822060e8a704a380bfae50c437031fbc07fe34c2
ssdeep: 12288:HPXhI+EMSBVC62W9IU029/xbaUstGH502A:vRI+ZeVCZW2mxH5q
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: AaA.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: AaA.exe

Ursu.82237 also known as:

K7AntiVirusRiskware ( 0040eff71 )
LionicTrojan.MSIL.Crypt.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader5.3884
CynetMalicious (score: 99)
ALYacGen:Variant.Ursu.82237
CylanceUnsafe
ZillyaTrojan.Crypt.Win32.41029
SangforTrojan.MSIL.Generic.ky
CrowdStrikewin/malicious_confidence_90% (D)
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.fdad8e
CyrenW32/MSIL_Kryptik.APC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.MXX
APEXMalicious
AvastMSIL:GenMalicious-BFR [Trj]
KasperskyHEUR:Trojan.MSIL.Generic
BitDefenderGen:Variant.Ursu.82237
NANO-AntivirusTrojan.Win32.Crypt.exanoj
MicroWorld-eScanGen:Variant.Ursu.82237
TencentMsil.Trojan.Generic.Alir
Ad-AwareGen:Variant.Ursu.82237
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34294.Hm0@aeswnehi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.ed3de6ffdad8e3cb
EmsisoftGen:Variant.Ursu.82237 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.ihhx
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2405DD0
MicrosoftTrojan:Win32/Skeeyah.A!bit
GDataGen:Variant.Ursu.82237
AhnLab-V3Trojan/Win32.RL_Generic.C3459570
McAfeeArtemis!ED3DE6FFDAD8
MAXmalware (ai score=95)
VBA32Trojan.MSIL.Crypt
MalwarebytesMalware.AI.1917339549
PandaTrj/GdSda.A
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Generic.AP.164C5C!tr
AVGMSIL:GenMalicious-BFR [Trj]
Paloaltogeneric.ml

How to remove Ursu.82237?

Ursu.82237 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment