Malware

Ursu.885472 malicious file

Malware Removal

The Ursu.885472 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.885472 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics
  • Unusual version info supplied for binary
  • Uses suspicious command line tools or Windows utilities

How to determine Ursu.885472?


File Info:

crc32: 1A3A6BA0
md5: b4c51c0d66cc89d1a014185666480a69
name: B4C51C0D66CC89D1A014185666480A69.mlw
sha1: ade98497b70970fd10dd9ee3caf8f08dff73bf12
sha256: b3d307b03c89ae53d024271e6d240eb6fb241603c0aaece512b16eef9f54a452
sha512: 35f2b9d9cb69d869c63fed7fc614b9f5bfe7fbe0e6b64c8debe234ab26ea85ffa25e50f0ae5c69037782859ab6a6108ad2cc61715ca0c1d8edd82096dd7415b9
ssdeep: 1536:5MbFCqIv46g0vI3YHEzK019BPQ2+LW4fHcihonUeP:5MBCqFFf4LW4f8uonn
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft 2012
Assembly Version: 1.0.0.0
InternalName: Fire-toll For SEO Masters.exe
FileVersion: 1.0.0.0
CompanyName: Fire-SOFT
ProductName: Fire-toll For SEO MAsters
ProductVersion: 1.0.0.0
FileDescription: Fire-toll For SEO MAsters
OriginalFilename: Fire-toll For SEO Masters.exe

Ursu.885472 also known as:

DrWebTrojan.KillProc.20697
CynetMalicious (score: 99)
ALYacGen:Variant.Ursu.885472
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.1732
SangforTrojan.Win32.Save.a
Cybereasonmalicious.d66cc8
SymantecTrojan.Gen
ESET-NOD32MSIL/LockScreen.BW
APEXMalicious
AvastMSIL:LockScreen-AI [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.885472
NANO-AntivirusTrojan.Win32.Blocker.bcvbrq
MicroWorld-eScanGen:Variant.Ursu.885472
TencentWin32.Trojan.Blocker.Pgmn
Ad-AwareGen:Variant.Ursu.885472
SophosMal/Generic-S
ComodoMalware@#21il4r8w05rn5
BitDefenderThetaGen:NN.ZemsilF.34790.dm0@aSIPs7h
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRansom-BJ
FireEyeGen:Variant.Ursu.885472
EmsisoftGen:Variant.Ursu.885472 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Blocker.bdg
AviraHEUR/AGEN.1109632
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Genasom.KT
GDataGen:Variant.Ursu.885472
AhnLab-V3Trojan/Win32.Blocker.R46895
McAfeeRansom-BJ
MAXmalware (ai score=83)
VBA32Trojan.MSIL.gen.16
MalwarebytesMalware.AI.681189123
PandaTrj/CI.A
IkarusTrojan-Ransom.Blocker
FortinetW32/Blocker.WYG!tr
AVGMSIL:LockScreen-AI [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Genasom.HgAASSAA

How to remove Ursu.885472?

Ursu.885472 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment