Malware

Ursu.854090 malicious file

Malware Removal

The Ursu.854090 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.854090 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.854090?


File Info:

crc32: 10A9078B
md5: c2b54be080b01c073362d5b9586551cc
name: C2B54BE080B01C073362D5B9586551CC.mlw
sha1: 74ea20627b486261e7a08579ae428e293b4c60d4
sha256: c8337abc2e85381e3bcad2b7b8b868fbac26960d4d1c8ebc729737a1cd365a85
sha512: 12bc42184635f0c68fbaa9846155d8611cdbbbaedbc4adb64d5b6a26ea740457f8303aabe55ac3675267e0d092136b318087be422830937e511126ce66fe379c
ssdeep: 6144:WS+5XgDpdDt+VcCBdFlC2UgZ8lxbL/UzfZD6f7KVCGipSChT:WS+1gDpdDtmBjlC2UgZWxbLczfZDGK8
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: (C) Techsoft
InternalName: setup
FileVersion: 1,0,0,0
CompanyName: Techsoft
LegalTrademarks: (C) Techsoft
ProductName: Installer
ProductVersion: 1,0,0,0
FileDescription: Installer
OriginalFilename: setup.exe
Translation: 0x0409 0x04e4

Ursu.854090 also known as:

K7AntiVirusTrojan ( 004ccea91 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.Ursu.854090
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.2969
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Filecoder.ebaba47f
K7GWTrojan ( 004ccea91 )
Cybereasonmalicious.080b01
SymantecRansom.EncRaaS!g1
ESET-NOD32a variant of Win32/Filecoder.EZ
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.854090
NANO-AntivirusTrojan.Win32.Taranis.flsajn
MicroWorld-eScanGen:Variant.Ursu.854090
TencentMalware.Win32.Gencirc.10c2b54a
Ad-AwareGen:Variant.Ursu.854090
ComodoMalware@#1eyphmpgdy57b
BitDefenderThetaGen:NN.ZexaF.34142.vG0@auvExRmi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
FireEyeGeneric.mg.c2b54be080b01c07
EmsisoftGen:Variant.Ursu.854090 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.fhnlb
AviraTR/Taranis.2722
Antiy-AVLTrojan/Generic.ASMalwS.1799982
KingsoftWin32.Heur.KVMH008.a.(kcloud)
MicrosoftRansom:Win32/Sarento
ArcabitTrojan.Ursu.DD084A
GDataGen:Variant.Ursu.854090
AhnLab-V3Trojan/Win32.Ransom.R199891
Acronissuspicious
McAfeeArtemis!C2B54BE080B0
MAXmalware (ai score=80)
VBA32TrojanRansom.Sarento
MalwarebytesMalware.AI.4112366640
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.90 (RDML:zV2pcDlUKCbFPcJ7lzDIzg)
YandexTrojan.GenAsa!JDo2/AEC4/o
IkarusTrojan.Win32.Filecoder
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.325CB!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ursu.854090?

Ursu.854090 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment