Malware

Should I remove “Application.Ursu.781949”?

Malware Removal

The Application.Ursu.781949 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Application.Ursu.781949 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Application.Ursu.781949?


File Info:

name: 7831D4D7BB75DA94DA8E.mlw
path: /opt/CAPEv2/storage/binaries/02c54c769ecca0edb36d85784ce464a1c676823801d86eddfe52b5956e723059
crc32: EABAED6B
md5: 7831d4d7bb75da94da8ea6915f4ed872
sha1: e6d9be9f398fe61f8639af87b44cd06990b4e67f
sha256: 02c54c769ecca0edb36d85784ce464a1c676823801d86eddfe52b5956e723059
sha512: b49842d361af9e25ce02605e16905193cfbecfa12c00d5d0961c0f7fb0f366b5324a275736cda392f04043f11fc4df24db45760e55ec700d6f490845ded10c86
ssdeep: 6144:PvJJz7HKNS9q+CTaaWcvkaTBAaBCgyRW+afhyii1QKLX9TAZLu7D62xJKgkFNWhL:eNN3aCvka8RL1Qy0UtIWhWmXA9
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1B394E0345B9C9142CBCEC339F0E646C046714726BE83F75A642C6EA66A533C64E277CE
sha3_384: 805c099d0d66bb72bc25f2c4c0a9067fd170b3d14aa9e1c344b56918a43daaefae9b54c73475bd24e81534e5b46128e3
ep_bytes: ff2500404400025200c2420000015cc6
timestamp: 2084-03-24 09:51:08

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: KWScreper
FileVersion: 1.0.0.0
InternalName: KWScreper.exe
LegalCopyright: Copyright © 2022
LegalTrademarks:
OriginalFilename: KWScreper.exe
ProductName: KWScreper
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Application.Ursu.781949 also known as:

BkavW32.AIDetectNet.01
CynetMalicious (score: 100)
CylanceUnsafe
SangforVirus.Win32.Save.a
BitDefenderGen:Variant.Application.Ursu.781949
Cybereasonmalicious.7bb75d
CyrenW32/MSIL_Troj.NT.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.VMProtect.ACR
APEXMalicious
MicroWorld-eScanGen:Variant.Application.Ursu.781949
Ad-AwareGen:Variant.Application.Ursu.781949
SophosGeneric ML PUA (PUA)
F-SecureHeuristic.HEUR/AGEN.1247154
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.7831d4d7bb75da94
EmsisoftGen:Variant.Application.Ursu.781949 (B)
IkarusTrojan.MSIL.Vmprotect
GDataGen:Variant.Application.Ursu.781949
AviraHEUR/AGEN.1247154
MAXmalware (ai score=77)
ArcabitTrojan.Application.Ursu.DBEE7D
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
AhnLab-V3Malware/Win32.RL_Generic.C4348595
Acronissuspicious
ALYacGen:Variant.Application.Ursu.781949
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:S8++ZWxFn3nJDncSa5y+ig)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZemsilF.34606.zu0@aW94rue
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Application.Ursu.781949?

Application.Ursu.781949 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment