Malware

Should I remove “Ursu.854926”?

Malware Removal

The Ursu.854926 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.854926 virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.854926?


File Info:

crc32: D113F1E1
md5: 9295255247d87e5d10fed6170ccc5b29
name: 9295255247D87E5D10FED6170CCC5B29.mlw
sha1: a9e5461b454f00bcb12e7ea6ba3889027fe22069
sha256: 0293b107d12f4e57338f4ed03fc548c7df4660023488d49b467506f1c2fae84c
sha512: 0cebb8037da8284b619a88e9a311d1ae266f2070e5ba074cdf10fffb43e327d3873427fdceea99c82123ba3a1a158484f6e40c4499b2b62e2a3a2d551f85a7b8
ssdeep: 24576:zay996H0pQeN/7DSBfWhtfvQ/A5T96H03Y:GxHoph7GBfWPA/dHX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: msinfo32.exe
FileVersion: 5.1.2600.0 (XPClient.010817-1148)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 5.1.2600.0
FileDescription: System Information
OriginalFilename: msinfo32.exe
Translation: 0x0409 0x04b0

Ursu.854926 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen5.28081
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.854926
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Trash.6e2a2670
Cybereasonmalicious.247d87
BaiduWin32.Worm.Agent.u
CyrenW32/Ipamor.CA.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Patched-AUS [Trj]
ClamAVWin.Malware.Kolabc-6736261-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.854926
NANO-AntivirusTrojan.Win32.TrjGen.fanttn
MicroWorld-eScanGen:Variant.Ursu.854926
TencentVirus.Win32.Kolabc.aad
Ad-AwareGen:Variant.Ursu.854926
SophosML/PE-A
VIPRETrojan.Win32.Kolabc.gu (v)
McAfee-GW-EditionBehavesLike.Win32.Dropper.dm
FireEyeGeneric.mg.9295255247d87e5d
EmsisoftGen:Variant.Ursu.854926 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Trash.Gen2
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASVirus.310
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Ursu.DD0B8E
GDataWin32.Trojan-Dropper.Rbot.A
AhnLab-V3Worm/Win32.Kolabc.R68112
McAfeeGeneric-FANE!9295255247D8
MAXmalware (ai score=81)
VBA32Exploit.RpcDcom
PandaTrj/CI.A
IkarusBackdoor.Win32.Rbot
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/DCom.AA!tr
AVGWin32:Patched-AUS [Trj]
Paloaltogeneric.ml

How to remove Ursu.854926?

Ursu.854926 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment