Malware

Ursu.881458 (B) removal instruction

Malware Removal

The Ursu.881458 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.881458 (B) virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Ursu.881458 (B)?


File Info:

crc32: 8E03AADC
md5: 72c6f71df396053abf138b1a8b66bd58
name: 72C6F71DF396053ABF138B1A8B66BD58.mlw
sha1: b3a55e53653ffe9303dd16fadf14cc252b27f6f4
sha256: 89a88ea456e907c8c912709897f598e21a3c3d1fd28d80d7d6bd1f1c9dd629e6
sha512: f4f411fc1839c198a72de2711234d7cd59ca9907218f14e4295d6efc6a1a0e778b53155897046fdd5e5a369eaa9304fdd343185c6433d2e741597f4e11495163
ssdeep: 6144:OcWvAzNGlSUKmh+ulVefa5SVZCrUYONO1JYdakjvPBgaG/xweYyvv:BQc0llvJ/edj/jNOTrkjZgj6e3
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2020-2021 by David Xanatos (xanasoft.com)
Assembly Version: 5.49.7.0
InternalName: ConsoleApp9.exe
FileVersion: 5.49.7.0
CompanyName: sandboxie-plus.com
LegalTrademarks:
Comments: Sandboxie Installer
ProductName: Sandboxie
ProductVersion: 5.49.7.0
FileDescription: Sandboxie Installer
OriginalFilename: ConsoleApp9.exe

Ursu.881458 (B) also known as:

K7AntiVirusTrojan ( 004bec131 )
Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.783
CynetMalicious (score: 100)
CAT-QuickHealTrojanDownloader.MSIL
ALYacGen:Variant.Ursu.881458
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Maldoc.ali2000008
K7GWTrojan ( 004bec131 )
Cybereasonmalicious.df3960
CyrenW32/MSIL_Kryptik.EIC.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/NanoCore.E
ZonerTrojan.Win32.111605
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan-Downloader.MSIL.Seraph.gen
BitDefenderGen:Variant.Ursu.881458
ViRobotTrojan.Win32.Z.Ursu.279040
MicroWorld-eScanGen:Variant.Ursu.881458
Ad-AwareGen:Variant.Ursu.881458
SophosMal/Generic-S + Troj/NanoCr-MM
ComodoMalware@#31wpbsloub49t
BitDefenderThetaGen:NN.ZemsilF.34692.rm0@aCoOIkh
TrendMicroTROJ_FRS.0NA103EV21
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.72c6f71df396053a
EmsisoftGen:Variant.Ursu.881458 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.Nanocore.xbpqw
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:MSIL/AgentTesla!MTB
GDataMSIL.Trojan.BSE.XNY6ZA
McAfeeArtemis!72C6F71DF396
MAXmalware (ai score=88)
MalwarebytesMalware.AI.1476596295
TrendMicro-HouseCallTROJ_FRS.0NA103EV21
IkarusTrojan.MSIL.Inject
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Ursu.881458 (B)?

Ursu.881458 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment