Malware

Ursu.850203 removal tips

Malware Removal

The Ursu.850203 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.850203 virus can do?

  • Executable code extraction
  • Unconventionial language used in binary resources: Turkish
  • Anomalous binary characteristics

How to determine Ursu.850203?


File Info:

crc32: 423B6DB6
md5: 9bd7923ca2946e30b18766c44466f97d
name: 9BD7923CA2946E30B18766C44466F97D.mlw
sha1: 30b114d80c31a01732749626123cd5c79a64f392
sha256: 09c8183e7d6a46caa943985504a678348b9ebbc8ab345dace441818db62bb603
sha512: 471624c382372aa80a9922fa2cf4d07091ba7c48388ae25f6d53b280c33baec4860a4738aacf11bc812549a98e051045464c5b719cf3a7377f1fadb7521dfd52
ssdeep: 6144:GiOXAEtT+kuYA2cesGdNYvy4WhkN/yV9vJGh7yVS8Jl4Nl6ZyFVtCbXNKQWBzcRS:ON+kuYvIiJl4Nl6ZcVtCTNKQWBzcRPwD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
ProductVersion: 1.00
InternalName: Explorer
FileVersion: 1.00
OriginalFilename: Explorer.exe
ProductName: Explorer

Ursu.850203 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusSpyware ( 0050eb711 )
DrWebTrojan.MulDrop6.44068
CynetMalicious (score: 85)
McAfeeGenericRXBS-EV!9BD7923CA294
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.34725
SangforTrojan.Win32.Save.a
K7GWSpyware ( 0050eb711 )
Cybereasonmalicious.ca2946
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Spy.VB.OEN
APEXMalicious
AvastWin32:Malware-gen
BitDefenderGen:Variant.Ursu.850203
NANO-AntivirusTrojan.Win32.Blocker.fjpnhb
MicroWorld-eScanGen:Variant.Ursu.850203
Ad-AwareGen:Variant.Ursu.850203
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZevbaF.34628.vm0@a4@iorfO
McAfee-GW-EditionGenericRXBS-EV!9BD7923CA294
FireEyeGeneric.mg.9bd7923ca2946e30
EmsisoftGen:Variant.Ursu.850203 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Blocker.dqa
AviraHEUR/AGEN.1131398
MicrosoftTrojan:Win32/Glupteba!ml
ArcabitTrojan.Ursu.DCF91B
GDataGen:Variant.Ursu.850203
AhnLab-V3Trojan/Win32.Blocker.R202502
VBA32Hoax.Blocker
MAXmalware (ai score=84)
MalwarebytesTrojan.VBCrypt
PandaTrj/CI.A
RisingRansom.Blocker!8.12A (C64:YzY0OsyVWXh2+gPY)
YandexTrojan.GenAsa!efSn5d9IICo
FortinetW32/Generic.AC.3521411
AVGWin32:Malware-gen

How to remove Ursu.850203?

Ursu.850203 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment