Malware

Ursu.958517 malicious file

Malware Removal

The Ursu.958517 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.958517 virus can do?

  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs

How to determine Ursu.958517?


File Info:

crc32: 2D43B61A
md5: 7eae6d258a7636277d12d5a891cdd31b
name: windlogs.exe
sha1: 0afdfb44b4e3f50b191cf378b721c86c0a2770d0
sha256: 37fc86b821e26bcc749d29a52eb553f4414198e6b0afb2f2ebcecfb3ad6a16f7
sha512: 13d2aaf0d62f017e2721ada9afd6a30066927ae7117ced57be4c9c67711be6b41684d9ce272a635c8032784d8701cd87d473def8ce6a220b6c23fda2f62bd42a
ssdeep: 24576:5HLmCiIhiX9xbg2KA8gY6EK7/sqpUJmLocJp3l9:q5p5jEK7/svRMR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ursu.958517 also known as:

MicroWorld-eScanGen:Variant.Ursu.958517
FireEyeGeneric.mg.7eae6d258a763627
McAfeeRDN/Generic BackDoor
MalwarebytesTrojan.Banker
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Agent.m!c
SangforMalware
K7AntiVirusTrojan ( 005644791 )
BitDefenderGen:Variant.Ursu.958517
K7GWTrojan ( 005644791 )
Cybereasonmalicious.58a763
TrendMicroTROJ_GEN.R002C0DGQ20
CyrenW32/Trojan.HFYM-5119
SymantecTrojan.Gen.MBT
APEXMalicious
AvastWin32:Trojan-gen
GDataGen:Variant.Ursu.958517
KasperskyBackdoor.Win32.Agent.awye
AlibabaBackdoor:Win32/Protos.27b
NANO-AntivirusTrojan.Win32.Agent.cekuh
TencentWin32.Backdoor.Agent.Alte
Endgamemalicious (high confidence)
SophosMal/Generic-S
ComodoMalware@#50is87bgg0in
F-SecureTrojan.TR/AD.Protos.ybjwz
DrWebTrojan.Siggen7.20605
Invinceaheuristic
EmsisoftGen:Variant.Ursu.958517 (B)
IkarusTrojan.Win32.Clipbanker
AviraTR/AD.Protos.ybjwz
MAXmalware (ai score=100)
Antiy-AVLTrojan[Backdoor]/Win32.Agent
MicrosoftBackdoor:Win32/LimeRat.YA!MTB
ArcabitTrojan.Ursu.DEA035
ZoneAlarmBackdoor.Win32.Agent.awye
CynetMalicious (score: 85)
BitDefenderThetaAI:Packer.D6EFB9151F
ALYacGen:Variant.Ursu.958517
VBA32BScope.Trojan.Tiggre
CylanceUnsafe
PandaTrj/CI.A
ESET-NOD32a variant of Win32/ClipBanker.LC
TrendMicro-HouseCallTROJ_GEN.R002C0DGQ20
RisingDownloader.Agent/VBS!1.BA1B (CLASSIC:bWQ1OrsGIysFriHuAZ0TMXyCBeQ)
FortinetW32/ClipBanker.LC!tr
Ad-AwareGen:Variant.Ursu.958517
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Win32/Backdoor.99b

How to remove Ursu.958517?

Ursu.958517 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment