Malware

Ursu.887634 removal

Malware Removal

The Ursu.887634 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.887634 virus can do?

  • Performs some HTTP requests
  • Creates an autorun.inf file
  • Installs itself for autorun at Windows startup
  • Checks for the presence of known devices from debuggers and forensic tools
  • Attempts to disable UAC
  • Attempts to modify UAC prompt behavior
  • Generates some ICMP traffic

How to determine Ursu.887634?


File Info:

crc32: 12B06A92
md5: f96de15712cd5cbd8a09991183eab80d
name: F96DE15712CD5CBD8A09991183EAB80D.mlw
sha1: 53fe958aacdc2b2980aff3763174a474fd34d40e
sha256: d75ec1a5e01b7730d5edd2b7bf9049bdcda9d67e714eb34aa5bfa596cc016591
sha512: 37f9de60da1c200ce8a15d045703353c2a0704ac9c98affc1c3e985233cc6ca75118b753cbccef704878b74b9c2b92d3bdd1dfcbc3dcf35879624d96f488528c
ssdeep: 12288:eiGzrLD1dy74nsJl5LAFPwYRsfB1SZygoA+bjCk0Re7KPXdyVVhb:uPLZdy74nsJbLAFIE61rgoA+bjCkKrP
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ursu.887634 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.887634
McAfeeGenericRXLY-ON!F96DE15712CD
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Ursu.887634
K7GWRiskware ( 0040eff71 )
ArcabitTrojan.Ursu.DD8B52
Ad-AwareGen:Variant.Ursu.887634
F-SecureTrojan.TR/AD.MedusaRansom.wojik
McAfee-GW-EditionGenericRXLY-ON!F96DE15712CD
FireEyeGeneric.mg.f96de15712cd5cbd
EmsisoftGen:Variant.Ursu.887634 (B)
AviraTR/AD.MedusaRansom.wojik
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Wacatac
MicrosoftTrojan:Win32/Wacatac.DD!ml
GDataGen:Variant.Ursu.887634
CynetMalicious (score: 90)
AhnLab-V3Trojan/Win32.Agent.R342416
ALYacGen:Variant.Ursu.887634
MalwarebytesSpyware.PasswordStealer
PandaTrj/GdSda.A
RisingTrojan.Ymacco!8.11BE1 (C64:YzY0OvlRzLqL35Fh)
YandexTrojan.AD!jcPzSBeNs+g
IkarusTrojan.MedusaRansom
eGambitUnsafe.AI_Score_86%
FortinetW32/MedusaRansom.WOJI!tr
BitDefenderThetaGen:NN.ZexaF.34590.LuW@aGFs2Vfi
AVGWin32:Malware-gen
Cybereasonmalicious.712cd5
AvastWin32:Malware-gen

How to remove Ursu.887634?

Ursu.887634 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment