Backdoor

Backdoor:Win32/Ursap!pz information

Malware Removal

The Backdoor:Win32/Ursap!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Ursap!pz virus can do?

  • Sample contains Overlay data
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Backdoor:Win32/Ursap!pz?


File Info:

name: 215DE52DDB56C52BA069.mlw
path: /opt/CAPEv2/storage/binaries/70ba860f9c163c768c0a2abea3f2a823c045219b6ca2e05c51b86ec55fcd255a
crc32: E1D0464A
md5: 215de52ddb56c52ba069bbf27a621ae0
sha1: 4cbca2c795ca78406594444c49887b4514ce6220
sha256: 70ba860f9c163c768c0a2abea3f2a823c045219b6ca2e05c51b86ec55fcd255a
sha512: 120b4dee043195ab582fab6eeb5d078fc60bac407f9487122f20525e5144bbc7842ab4bb315e49ec55cc2c3708e9aecde086261d2490e5e8777d2b6dd9d2d7cb
ssdeep: 3072:OFc+FoEGHm84TRzJIu5CjoFF5fUxqkts9MeZ3fxXltGapQe5hdjqLnQmv+ky:dh4ZJI3joFFhUxveZ3fpDpQYhFqF
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T136248D047BA4D436F2B72E31A476D3948E76B9717C79C50F67920A6E0E30A98ED32317
sha3_384: e9828534c7e5a69e927c05f98bb51dc7c1a7dc30a7fffeee30f1faba7f7d1224dc11879f7762283e3873bdfc64152b95
ep_bytes: 8bff558bec837d0c017505e8344e0000
timestamp: 2007-12-19 00:53:58

Version Info:

Comments:
CompanyName: Seagate Software, Inc.
FileDescription: Word for Windows Export Format DLL for Crystal Reports
FileVersion: 8.5.0.92
InternalName: uxfwordw
LegalCopyright: Copyright (c) 1991-2001 Seagate Software
LegalTrademarks: Crystal Reports is a trademark of Seagate Software, Inc. or one of its subsidiaries
OriginalFilename: u2fwordw.dll
PrivateBuild:
ProductName: Crystal Reports
ProductVersion: 8.5.0.211
SpecialBuild:
BuildDate: 2001/02/03 01:25:19
Translation: 0x0409 0x04e4

Backdoor:Win32/Ursap!pz also known as:

LionicTrojan.Win32.Generic.lEOt
AVGWin32:Reveton-HR [Trj]
Elasticmalicious (high confidence)
DrWebTrojan.Fakealert.55861
MicroWorld-eScanGen:Variant.Ser.Jaik.4419
FireEyeGeneric.mg.215de52ddb56c52b
SkyhighRansom-ABD.gen.d
McAfeeRansom-ABD.gen.d
ZillyaTrojan.FakeAV.Win32.238043
SangforSuspicious.Win32.Save.a
K7AntiVirusRansomware ( 005454081 )
AlibabaTrojan:Win32/Reveton.55c9abb6
K7GWRansomware ( 005454081 )
CrowdStrikewin/malicious_confidence_90% (W)
VirITTrojan.Win32.Foreign.THM
SymantecTrojan.Ransomlock!g26
tehtrisGeneric.Malware
ESET-NOD32Win32/Reveton.H
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Ransomlock-7
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Ser.Jaik.4419
NANO-AntivirusTrojan.Win32.RiskGen.bbkjkd
AvastWin32:Reveton-HR [Trj]
TencentMalware.Win32.Gencirc.10b3c475
EmsisoftGen:Variant.Ser.Jaik.4419 (B)
VIPREGen:Variant.Ser.Jaik.4419
TrendMicroTROJ_RANSOM.SMC4
SophosTroj/Zbot-CYS
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Generic.asjop
GoogleDetected
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Unknown
KingsoftWin32.Trojan.Generic.a
MicrosoftBackdoor:Win32/Ursap!pz
XcitiumMalware@#30nteehss5595
ArcabitTrojan.Ser.Jaik.D1143
ViRobotTrojan.Win32.A.Foreign.231424
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Ser.Jaik.4419
VaristW32/Trojan.KUPA-6140
AhnLab-V3Trojan/Win32.Ransomlock.R44642
ALYacGen:Variant.Ser.Jaik.4419
VBA32BScope.Trojan.FakeAlert
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_RANSOM.SMC4
RisingTrojan.Reveton!8.AB (TFE:5:Cme8XEsLiWG)
YandexTrojan.GenAsa!tq5AopblIIU
IkarusTrojan.Win32.Reveton
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.AORE!tr
ZonerTrojan.Win32.11927
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Reveton.H

How to remove Backdoor:Win32/Ursap!pz?

Backdoor:Win32/Ursap!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment