Malware

How to remove “Ursu.938063”?

Malware Removal

The Ursu.938063 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.938063 virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz

How to determine Ursu.938063?


File Info:

crc32: 83804F96
md5: 855dc7f59e493ce7a5574d8c6a597cb7
name: 855DC7F59E493CE7A5574D8C6A597CB7.mlw
sha1: c6871576a354f6d330dd5927a825f847f8be468f
sha256: 34b48f88f9b99dec3e3d0a7689af6e304338bdb72171cd2ac8de05a34c27f3aa
sha512: efa113c9bb6470a69aef810aefade096d40a1851768608659e059e3f2ce179604d495717688d595f17656584d7bbddfc70e5b19ac6ec7819f8c1cd321f936f8d
ssdeep: 192:xPGZg5qijWRwQEWtTY28NUBEoVE8G7zP7fus5:xPfqijrQEWt18NUBlVfEzDf1
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2020
Assembly Version: 1.0.0.0
InternalName: letoni.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: letoni
ProductVersion: 1.0.0.0
FileDescription: letoni
OriginalFilename: letoni.exe

Ursu.938063 also known as:

LionicTrojan.Win32.Generic.4!c
ALYacGen:Variant.Ursu.938063
CylanceUnsafe
ZillyaTrojan.Generic.Win32.1085566
SangforTrojan.Win32.Save.a
AlibabaTrojan:Win32/Generic.e812c0f6
K7GWTrojan ( 0056d7e81 )
K7AntiVirusTrojan ( 0056d7e81 )
CyrenW32/Trojan.YNIP-7954
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/ClipBanker.RH
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.938063
NANO-AntivirusTrojan.Win32.Mlw.hoxkoi
MicroWorld-eScanGen:Variant.Ursu.938063
TencentWin32.Trojan.Generic.Dzjx
Ad-AwareGen:Variant.Ursu.938063
SophosMal/Generic-S
ComodoMalware@#4e5pe1zkt1ut
F-SecureTrojan.TR/Spy.ClipBanker.jhmwi
BitDefenderThetaGen:NN.ZemsilCO.34058.am0@au1nUMh
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXGG-KX!855DC7F59E49
FireEyeGeneric.mg.855dc7f59e493ce7
EmsisoftGen:Variant.Ursu.938063 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Generic.fthcu
AviraTR/Spy.ClipBanker.jhmwi
Antiy-AVLTrojan/Generic.ASMalwS.30B0B90
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftVirTool:MSIL/SharpStay
ArcabitTrojan.Ursu.DE504F
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ursu.938063
AhnLab-V3Trojan/Win32.ClipBanker.C4190900
McAfeeGenericRXGG-KX!855DC7F59E49
MAXmalware (ai score=88)
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.Bladabindi
PandaTrj/GdSda.A
IkarusTrojan.MSIL.ClipBanker
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.KX!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HgIASOQA

How to remove Ursu.938063?

Ursu.938063 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment