Adware

Adware.Ursu.86662 removal instruction

Malware Removal

The Adware.Ursu.86662 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Adware.Ursu.86662 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Collects information to fingerprint the system

How to determine Adware.Ursu.86662?


File Info:

name: 2046CFE4BE4991FA9C74.mlw
path: /opt/CAPEv2/storage/binaries/3e36657f20ac447d737f8c59dabbe4687852bd07be2d2990e23dffed5815e7f2
crc32: 7A394BCF
md5: 2046cfe4be4991fa9c74e8991218f734
sha1: 37179e4edd7fc20b3d0a38308336133ade3aa235
sha256: 3e36657f20ac447d737f8c59dabbe4687852bd07be2d2990e23dffed5815e7f2
sha512: 17e2e74fc6d96fb0edce37a568a2af81adf3a72a90367ab90beefffaa29dd809a277b7b440f14e96b2cc64e938b5130ce8de2bb1e4cf2ad490579c101a53f7bb
ssdeep: 3072:7w4gnScGuDI2dcWgir4pKW2dNemHVvCK4qNAZ0R8JQB0Ejtjwg:7z2DgC4pZweSaKNrR8JQeEjpwg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14ED3011BB3F1DCEBD1A296B11EBFA739E3BA684162A0430307440F77BE1094B25576D6
sha3_384: 2fa01938c7730f0002cda4e6a3e552c566db30f9a09b2b32dc0aabb7bafcda5016b076bda21bb46bb06d31e229122027
ep_bytes: 81ec8401000053565733db6801800000
timestamp: 2016-07-25 00:55:54

Version Info:

CompanyName:
FileDescription:
FileVersion: 1.0.0.695
LegalCopyright: © 2017
ProductName:
Translation: 0x0409 0x04e4

Adware.Ursu.86662 also known as:

LionicAdware.Win32.Generic.2!c
MicroWorld-eScanGen:Variant.Adware.Ursu.86662
ALYacGen:Variant.Adware.Ursu.86662
CylanceUnsafe
VIPREGen:Variant.Adware.Ursu.86662
SangforAdware.Win32.Amonetize.Gen7
K7AntiVirusTrojan ( 700000121 )
AlibabaAdWare:MSIL/Amonetize.aaea3b1c
K7GWTrojan ( 700000121 )
Cybereasonmalicious.4be499
CyrenW32/S-cd771cd3!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Amonetize.AF potentially unwanted
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderGen:Variant.Adware.Ursu.86662
NANO-AntivirusTrojan.Win32.Amonetize.eteqxu
CynetMalicious (score: 100)
AvastWin32:Evo-gen [Trj]
TencentWin32.AdWare.Generic.Rgil
Ad-AwareGen:Variant.Adware.Ursu.86662
EmsisoftGen:Variant.Adware.Ursu.86662 (B)
ComodoApplication.MSIL.Amonetize.AEF@6ji1v1
F-SecureAdware.ADWARE/Amonetize.Gen7
DrWebTrojan.DownLoader22.21178
ZillyaAdware.Generic.Win32.137312
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SentinelOneStatic AI – Suspicious PE
Trapminemalicious.high.ml.score
FireEyeGen:Variant.Adware.Ursu.86662
SophosGeneric PUA DH (PUA)
APEXMalicious
GDataGen:Variant.Adware.Ursu.86662
AviraADWARE/Amonetize.Gen7
Antiy-AVLGrayWare[AdWare]/Win32.Amonetize.ccjp
ArcabitTrojan.Adware.Ursu.D15286
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.Generic
MicrosoftTrojan:Win32/Occamy.C
GoogleDetected
AhnLab-V3PUP/Win32.Amonetize.C1548791
McAfeeArtemis!2046CFE4BE49
MAXmalware (ai score=98)
MalwarebytesGeneric.Malware/Suspicious
RisingTrojan.Generic@AI.95 (RDML:rzaC+QfEqJ/nrqP/fmbjPQ)
IkarusPUA.MSIL.Amonetize
FortinetW32/Generic!tr
AVGWin32:Evo-gen [Trj]
PandaTrj/CI.A
CrowdStrikewin/grayware_confidence_100% (W)

How to remove Adware.Ursu.86662?

Adware.Ursu.86662 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment