Malware

Ursu.96429 removal instruction

Malware Removal

The Ursu.96429 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.96429 virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ursu.96429?


File Info:

crc32: 4F5850C1
md5: cc0ad3679afc7ad0391a7384da311090
name: CC0AD3679AFC7AD0391A7384DA311090.mlw
sha1: 41381e89bbfb9d8fd25ea7b84bda82813911c6f3
sha256: 60173365335a490ecc5d3be00badab7ac68dfe301c9836fb8d6d4c3acda5d4b7
sha512: 90e4aa6dccd1cabcddf68ca24372b0e246e19848441d87549d8b7d8cc59894a1dd0a35edc4914d697dd46924bc6238d5e60db55558e122072404c4d1002c70bf
ssdeep: 96:QkjJ7LG9TbLGxWuTRqlNzKDhFrsDgZcaNzOT8mY877YVbFEAy3+xx4zNt:QkjZ2PLGxWig3GzwvaNCT8K7x332a
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: stealer.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: stealer.exe

Ursu.96429 also known as:

K7AntiVirusTrojan ( 700000121 )
LionicTrojan.MSIL.Stealer.l!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.96429
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1071636
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 700000121 )
Cybereasonmalicious.79afc7
CyrenW32/Stimilik.B.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/PSW.CoinStealer.BT
APEXMalicious
AvastWin32:CoinThief-A [Trj]
KasperskyTrojan-Spy.MSIL.Stealer.ll
BitDefenderGen:Variant.Ursu.96429
NANO-AntivirusTrojan.Win32.Stealer.ezfzjc
MicroWorld-eScanGen:Variant.Ursu.96429
TencentMsil.Trojan-spy.Stealer.Sxxy
Ad-AwareGen:Variant.Ursu.96429
SophosMal/Generic-S
ComodoTrojWare.MSIL.CoinStealer.BT@7j5i95
BitDefenderThetaGen:NN.ZemsilF.34236.am0@au!CRih
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_FRS.VSN17D18
McAfee-GW-EditionBehavesLike.Win32.Generic.zt
FireEyeGeneric.mg.cc0ad3679afc7ad0
EmsisoftGen:Variant.Ursu.96429 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.MSIL.wgl
AviraHEUR/AGEN.1124739
Antiy-AVLTrojan/Generic.ASMalwS.25BF1D4
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Ursu.D178AD
SUPERAntiSpywareTrojan.Agent/Gen-Stealer
GDataMSIL.Trojan.CoinStealer.E
McAfeeGeneric.dsl
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.Agent.P
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_FRS.VSN17D18
YandexTrojanSpy.Stealer!BgX2XtPUzK8
IkarusTrojan.MSIL.PSW
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/CoinStealer.BT!tr.pws
AVGWin32:CoinThief-A [Trj]
Paloaltogeneric.ml

How to remove Ursu.96429?

Ursu.96429 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment