Malware

Ursu.847021 malicious file

Malware Removal

The Ursu.847021 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.847021 virus can do?

  • Network activity detected but not expressed in API logs

How to determine Ursu.847021?


File Info:

crc32: 4AC30C56
md5: dd6dcb8a941f75334056d73f68e5a288
name: DD6DCB8A941F75334056D73F68E5A288.mlw
sha1: c9419f97d3dd05bf0b55653a72040f8e85e11708
sha256: c55e5cc5d530ccccb0ea084214dd3dfb7b67e0c1c27a5be69e637c6df8c4925c
sha512: 379859b9ce0d418eed0331b699fdac298860aea9d43a3fc6ff0e6fea2d534d8d80eb38fe88b158eda9d79d5b6dc9ff00c08c3c89322349a48422b9cf497320ca
ssdeep: 1536:RHhO/brfY53IcSssHPQOd7BdlC1npqKmY7:R4/brI49Q4dk10z
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
Assembly Version: 6.2.19041.906
InternalName: HelpPane.exe
FileVersion: 6.2.19041.906
CompanyName: Microsoft Corporation
LegalTrademarks:
Comments:
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.2.19041.906
FileDescription: Microsoft x5e2ex52a9x548cx652fx6301
OriginalFilename: HelpPane.exe

Ursu.847021 also known as:

Elasticmalicious (high confidence)
DrWebBackDoor.AsyncRATNET.1
CynetMalicious (score: 99)
McAfeeArtemis!DD6DCB8A941F
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/AmsiTamper.db280aba
Cybereasonmalicious.a941f7
CyrenW32/MSIL_Ransom.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.CFQ
APEXMalicious
AvastWin32:DropperX-gen [Drp]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.847021
MicroWorld-eScanGen:Variant.Ursu.847021
Ad-AwareGen:Variant.Ursu.847021
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34686.vm0@a0jYvll
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.dd6dcb8a941f7533
EmsisoftGen:Variant.Ursu.847021 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1121272
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/AmsiTamper.B
GDataGen:Variant.Ursu.847021
AhnLab-V3Trojan/Win.Agent.C4386732
MAXmalware (ai score=81)
MalwarebytesMalware.AI.3042426362
PandaTrj/GdSda.A
RisingTrojan.Agent!8.B1E (CLOUD)
IkarusTrojan.MSIL.Agent
FortinetMSIL/CoinMiner.CFQ!tr
AVGWin32:DropperX-gen [Drp]
Paloaltogeneric.ml

How to remove Ursu.847021?

Ursu.847021 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment