Adware

Adware.Ursu.1400 information

Malware Removal

The Adware.Ursu.1400 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Ursu.1400 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid

How to determine Adware.Ursu.1400?


File Info:

name: 3AF9336E697C9870B31F.mlw
path: /opt/CAPEv2/storage/binaries/aa7d217751bfa7a0bc0454601a83c727cb2ddf6758879b4820a5617626078e1f
crc32: 0A84F370
md5: 3af9336e697c9870b31fa61e26b7ad83
sha1: a8ee8c39b2a2af03564e97b3d0c1ac2ab601ddbc
sha256: aa7d217751bfa7a0bc0454601a83c727cb2ddf6758879b4820a5617626078e1f
sha512: 397e762fa1bd11e50f3506c47cb123cdd18b7e2b62f31baac41277da5526f3c3d7d251fe92319ba7ca42016b65b85134f0bee0ebdda5f0996b3b586b20014f13
ssdeep: 49152:vjX63VNZGiFWUNB1a+2frBG10SmK+RKDkCT4CkLwjj38L8my+CCdoss/zJiLjBea:vjAVy6yrBG108wKd4CkLwjj3lEY2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T164C59D107B84C236E5A301F19B2C9F6A442DAE712B6544C7E3C82E6E1970AD36F3775B
sha3_384: 4c1073d81c3b5c3dabbca858cc8cb16baef3ffbd8d565db627d626677e669a1793957cc8940a28343e11bb2b0e55f83b
ep_bytes: e8d1110100e97ffeffffff35f40b6600
timestamp: 2017-10-13 14:22:14

Version Info:

FileDescription: MailRuSputnik
FileVersion: 3.13.0.29
InternalName: MailRuSputnik
LegalCopyright: Copyright c 2005 - 2015
OriginalFilename: MailRuSputnik.exe
ProductName: MailRuSputnik
ProductVersion: 3.13.0.29
Translation: 0x0419 0x04e3

Adware.Ursu.1400 also known as:

LionicAdware.Win32.Machaer.2!c
DrWebTrojan.StartPage1.46816
MicroWorld-eScanGen:Variant.Adware.Ursu.1400
FireEyeGeneric.mg.3af9336e697c9870
McAfeeGenericRXDB-DL!3AF9336E697C
CylanceUnsafe
K7AntiVirusAdware ( 005005291 )
AlibabaAdWare:Win32/MailRu.0646fb10
K7GWAdware ( 005005291 )
Cybereasonmalicious.e697c9
CyrenW32/Trojan.BLA.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/MailRu.D potentially unwanted
ClamAVWin.Malware.Mailru-6984194-0
Kasperskynot-a-virus:HEUR:AdWare.Win32.Machaer.gen
BitDefenderGen:Variant.Adware.Ursu.1400
TencentMalware.Win32.Gencirc.11495905
Ad-AwareGen:Variant.Adware.Ursu.1400
EmsisoftApplication.InstallAd (A)
ComodoApplication.Win32.MailRu.C@6l8k5e
ZillyaTrojan.GenericKD.Win32.93497
McAfee-GW-EditionGenericRXDB-DL!3AF9336E697C
SophosGeneric PUA KI (PUA)
IkarusPUA.MailRu
GDataGen:Variant.Adware.Ursu.1400
JiangminTrojanDownloader.Dapato.cfw
WebrootW32.Adware.Gen
MAXmalware (ai score=99)
ArcabitTrojan.Adware.Ursu.D578
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Machaer.gen
MicrosoftTrojan:Win32/Occamy.AB
AhnLab-V3PUP/Win32.MailRu.C2201064
ALYacGen:Variant.Adware.Ursu.1400
VBA32TrojanDownloader.Dapato
YandexTrojan.GenAsa!aNSEkqvnAHc
SentinelOneStatic AI – Suspicious PE
MaxSecurenot-a-virus:Adware.Win32.Mail.RU
FortinetW32/Fareit.A
PandaPUP/Generic
CrowdStrikewin/grayware_confidence_100% (D)

How to remove Adware.Ursu.1400?

Adware.Ursu.1400 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment