Malware

About “Ursu.880340” infection

Malware Removal

The Ursu.880340 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.880340 virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.880340?


File Info:

crc32: A9E2F8D9
md5: 86f1ed9d3f0381df0636961670a091a4
name: 86F1ED9D3F0381DF0636961670A091A4.mlw
sha1: 7cbbc7980faa8dee61a70e1ad1d20f091395b231
sha256: 7679d20528b33c6c5a8b7cf491fc888491e339c86e62a5a4cbe8412ee5a0e023
sha512: 1814f9d4260807ad95a46c602a560a5f1f013cfdcf40c8c43d27f72ef0a6396e67b3bbf9dd909be03a76d51e7d90e68795ede7201a6612ee3f25e8bef13af736
ssdeep: 96:Lxj8IQ04XFxlysSHuXjGnBLw0L62PlF0B26IEPKvTPgzzSLEOZvZI6Ux0l92e/N:u0kHlyMTiE2Pz0Y63Kvyz8ZIMUOd4oY
type: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: nitro_generator.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: nitro_generator.exe

Ursu.880340 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.PWS.DiscordNET.45
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.880340
CylanceUnsafe
SangforTrojan.Win32.Save.a
Cybereasonmalicious.d3f038
CyrenW32/MSIL_Discord.F.gen!Eldorado
ESET-NOD32a variant of MSIL/PSW.Discord.UP
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyHEUR:Trojan.MSIL.Witch.gen
BitDefenderGen:Variant.Ursu.880340
MicroWorld-eScanGen:Variant.Ursu.880340
TencentTrojan.Win32.Polyransom.b
Ad-AwareGen:Variant.Ursu.880340
SophosML/PE-A
BitDefenderThetaGen:NN.ZemsilF.34692.am0@aal0dhj
McAfee-GW-EditionGenericRXOL-RL!86F1ED9D3F03
FireEyeGeneric.mg.86f1ed9d3f0381df
EmsisoftGen:Variant.Ursu.880340 (B)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:MSIL/Disstl.ACH!MTB
ArcabitTrojan.Ursu.DD6ED4
ZoneAlarmHEUR:Trojan.MSIL.Witch.gen
GDataGen:Variant.Ursu.880340
AhnLab-V3Trojan/Win.Generic.C4451291
McAfeeGenericRXOL-RL!86F1ED9D3F03
MAXmalware (ai score=85)
MalwarebytesSpyware.DiscordStealer.MSIL
RisingStealer.Discord/MSIL!1.D5DE (CLASSIC)
IkarusTrojan.MSIL.PSW
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Discord.UP!tr
AVGWin32:TrojanX-gen [Trj]

How to remove Ursu.880340?

Ursu.880340 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment