Malware

What is “Ursu.898025”?

Malware Removal

The Ursu.898025 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.898025 virus can do?

  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine Ursu.898025?


File Info:

crc32: 0ECB77B9
md5: aa9a44911b2d773a7af4de3711bd825d
name: AA9A44911B2D773A7AF4DE3711BD825D.mlw
sha1: 8a5fdc1b9f31f9edf1fd9345ea586a6fc9588e03
sha256: d95b0644e9010f2b71d0efc44adf53ba8da56fd233787cde9d798287f127d821
sha512: 0fb520af9e17cdeb8c330b5a847f56d89aa7b8e3a346b47903fad350b1549b06288b1a58cebddd7016f5acb6600741ec31b159d368286ff179c54fbfb3927ff6
ssdeep: 192:0QdHWRDZdaGPcHL/yqzE1odW2XV1a/OL6zpKNIhGioictaetTI8U:tH3HL/HzEWWYaTcIgTY
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: OfficeClickToRun.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: OfficeClickToRun.exe

Ursu.898025 also known as:

K7AntiVirusTrojan ( 004f55fc1 )
LionicTrojan.Win32.Blocker.j!c
DrWebTrojan.MulDrop6.58806
CynetMalicious (score: 99)
ALYacGen:Variant.Ursu.898025
CylanceUnsafe
ZillyaTrojan.ClipBanker.Win32.4258
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/Blocker.512f0939
K7GWTrojan ( 004f55fc1 )
Cybereasonmalicious.11b2d7
ESET-NOD32a variant of MSIL/ClipBanker.O
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.jprb
BitDefenderGen:Variant.Ursu.898025
NANO-AntivirusTrojan.Win32.Blocker.egwnbb
MicroWorld-eScanGen:Variant.Ursu.898025
TencentWin32.Trojan.Blocker.Lorq
Ad-AwareGen:Variant.Ursu.898025
BitDefenderThetaGen:NN.ZemsilF.34170.gm0@aWYwCSn
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.aa9a44911b2d773a
EmsisoftGen:Variant.Ursu.898025 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.fgn
AviraHEUR/AGEN.1115181
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.1B9EF9C
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Skeeyah.A!rfn
GDataGen:Variant.Ursu.898025
AhnLab-V3Trojan/Win32.RL_Blocker.C4310373
McAfeeGeneric.all
MAXmalware (ai score=88)
VBA32TScope.Trojan.MSIL
MalwarebytesMachineLearning/Anomalous.97%
PandaTrj/GdSda.A
YandexTrojan.Blocker!OiuxbDJnHeo
IkarusTrojan.MSIL.ClipBanker
MaxSecureTrojan.Malware.101087039.susgen
FortinetMSIL/ClipBanker.O!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ursu.898025?

Ursu.898025 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment