Malware

How to remove “Ursu.887218”?

Malware Removal

The Ursu.887218 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.887218 virus can do?

  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.887218?


File Info:

crc32: D78ECC42
md5: 59b028deef9c5800f3bf08d1f2bd0362
name: 59B028DEEF9C5800F3BF08D1F2BD0362.mlw
sha1: 3479ca7aed596105a269288de3c6bd6798af75c9
sha256: b2987914e8813e3fb4b71fa1e52b35e5581abe7107b765761569dda2949bea93
sha512: 402373b611f5929fbba0a90a62bb30a8678c16c73633ace0bd1ff870d104a29fb2627c521b8f76cb8d3b0092cd479ef32972be1154cbd45cd0abbd79076c1dfd
ssdeep: 12288:zBw4tn8y3AGmEvX+3IdpvX5E6opcLyXTH+KUCBq:dFtNfmEvX+i/hopIyDHU4q
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0809 0x04b0

Ursu.887218 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 700000111 )
LionicTrojan.Win32.Blocker.j!c
DrWebTrojan.Encoder.7161
CynetMalicious (score: 100)
CAT-QuickHealRansom.Autoit.Stampado.A
ALYacGen:Variant.Ursu.887218
CylanceUnsafe
ZillyaWorm.Filecoder.Win32.207
AlibabaTrojan:Win32/Starter.ali1001008
K7GWTrojan ( 700000111 )
Cybereasonmalicious.eef9c5
ESET-NOD32Win32/Filecoder.Philadelphia.B
APEXMalicious
AvastINF:AutoRun-BI [Wrm]
KasperskyTrojan-Ransom.Win32.Blocker.jwgx
BitDefenderGen:Variant.Ursu.887218
NANO-AntivirusTrojan.Script.AuVir.ekpekr
MicroWorld-eScanGen:Variant.Ursu.887218
TencentWin32.Trojan.Blocker.Syia
Ad-AwareGen:Variant.Ursu.887218
SophosML/PE-A + Mal/Behav-043
ComodoMalware@#2g0x4u1k8euit
BitDefenderThetaAI:Packer.618F1AC817
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroRansom_STAMPADO.F117AC
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.59b028deef9c5800
EmsisoftGen:Variant.Ursu.887218 (B)
AviraDR/AutoIt.Gen
MicrosoftRansom:Win32/Stampado.A
ArcabitTrojan.Ursu.DD89B2
ZoneAlarmTrojan-Ransom.Win32.Blocker.jwgx
GDataGen:Variant.Ursu.887218
AhnLab-V3Trojan/Win32.Blocker.C1846041
McAfeeArtemis!59B028DEEF9C
MAXmalware (ai score=80)
PandaTrj/CI.A
TrendMicro-HouseCallRansom_STAMPADO.F117AC
RisingRansom.Philadelphia/Autoit!1.BA48 (CLASSIC)
YandexTrojan.Blocker!0NScW/B2AD8
IkarusWorm.Win32.Filecoder
MaxSecureTrojan.Malware.300983.susgen
FortinetAutoIt/Philadelphia.E!tr
AVGINF:AutoRun-BI [Wrm]
Paloaltogeneric.ml

How to remove Ursu.887218?

Ursu.887218 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment