Malware

Ursu.872999 removal guide

Malware Removal

The Ursu.872999 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.872999 virus can do?

  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Network activity detected but not expressed in API logs
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.872999?


File Info:

crc32: 5212C07B
md5: 29ec634f7a85ff39719410695d115776
name: 29EC634F7A85FF39719410695D115776.mlw
sha1: c3ef72b5864197636baa9e7220010d270c92acfa
sha256: 136c4570a60516190907c39a14a0c67de972a9f850a2cab1c82d588673f676d1
sha512: 87416ba9e6998864fb509a8f6f1298188976ff3553078a953389a02c7325681627f3c7ae0a0511d29c60825b7170ec64317289281913ee5e8284609e3c1971da
ssdeep: 1536:J3TrnmdtTcNPdqgs6KB/QD5bwNlZ3za3lBpicOwAmStv:JP5NPdIRQDSPZCpXS
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

LegalCopyright: (C) Software Corp.
InternalName: setup
FileVersion: 1,0,0,0
CompanyName: Software Corp.
LegalTrademarks: (C) Software Corp.
ProductName: Installer
ProductVersion: 1,0,0,0
FileDescription: Installer
OriginalFilename: setup.exe
Translation: 0x0409 0x04e4

Ursu.872999 also known as:

K7AntiVirusTrojan ( 0055e3ef1 )
LionicTrojan.Win32.Generic.4!c
DrWebTrojan.Encoder.4306
CynetMalicious (score: 99)
ALYacGen:Variant.Ursu.872999
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.4151
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.f7a85f
CyrenW32/Ransom.CB.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.EZ
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.872999
NANO-AntivirusTrojan.Win32.Encoder.ebqznl
MicroWorld-eScanGen:Variant.Ursu.872999
TencentMalware.Win32.Gencirc.10c22fd0
Ad-AwareGen:Variant.Ursu.872999
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1131979
BitDefenderThetaGen:NN.ZexaF.34110.fG0@aeGArZei
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CRYPRAAS.SMA1
McAfee-GW-EditionGenericR-IXK!29EC634F7A85
FireEyeGeneric.mg.29ec634f7a85ff39
EmsisoftGen:Variant.Ursu.872999 (B)
JiangminTrojan.Generic.aajwg
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1131979
eGambitUnsafe.AI_Score_94%
MicrosoftRansom:Win32/Sarento
SUPERAntiSpywareRansom.FileCryptor/Variant
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ursu.872999
AhnLab-V3Trojan/Win32.Ransom.C1947452
McAfeeGenericR-IXK!29EC634F7A85
MAXmalware (ai score=80)
VBA32Trojan.Encoder
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_CRYPRAAS.SMA1
YandexTrojan.GenAsa!w/gVp2pkYjo
IkarusTrojan-Ransom.Enigma
FortinetW32/Generic!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ursu.872999?

Ursu.872999 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment