Malware

Ser.Ursu.13887 removal guide

Malware Removal

The Ser.Ursu.13887 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Ursu.13887 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Ser.Ursu.13887?


File Info:

name: F883B7DFDE8AE22F6806.mlw
path: /opt/CAPEv2/storage/binaries/ef33f75e14ae9cdc01eeb677264ba578079a168b1e5be9f48a93e09a2c88dcdc
crc32: DE6D1848
md5: f883b7dfde8ae22f680688d0d07fa359
sha1: efb929314939b729bb9e927528e6b54286ac150e
sha256: ef33f75e14ae9cdc01eeb677264ba578079a168b1e5be9f48a93e09a2c88dcdc
sha512: 157089930b8a8c8d7b18e69075dd59003cfa53727df8307e14b28d4f064259fbe214417171a2bab9e6d6345a689fbfd565ac6145f5090b38c9481778ef35a4be
ssdeep: 49152:97m4444444444444444444444444444444444444444444444444444444yhQ:U444444444444444444444444444444m
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11DA5E070F4CA5F1BC00697FC09740E888FEF7D4A2456F65C3FB9A1CAE6D02455BA1AA1
sha3_384: 5d747f513159ee007128cf5acc5e51c0c6ab75d96b124dd65d8c0dd01e0587dc9bbd402238e47586e2823d81197ec343
ep_bytes: ff250020400000000000000000000000
timestamp: 2017-08-08 12:31:04

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Windows Command Processor
FileVersion: 10.0.14393.0 (rs1_release.160715-1616)
InternalName: cmd
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: Cmd.Exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.14393.0
Translation: 0x0409 0x04b0

Ser.Ursu.13887 also known as:

LionicTrojan.MSIL.Bladabindi.m!c
Elasticmalicious (high confidence)
DrWebBackDoor.Bladabindi.13678
MicroWorld-eScanGen:Variant.Ser.Ursu.13887
FireEyeGeneric.mg.f883b7dfde8ae22f
ALYacGen:Variant.Ser.Ursu.13887
CylanceUnsafe
SangforVirus.Win32.Save.a
K7AntiVirusTrojan ( 0051370c1 )
K7GWTrojan ( 0051370c1 )
Cybereasonmalicious.fde8ae
BitDefenderThetaGen:NN.ZemsilF.34182.jo0@ame5zFci
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.DDI
Paloaltogeneric.ml
BitDefenderGen:Variant.Ser.Ursu.13887
NANO-AntivirusTrojan.Win32.Bladabindi.erszde
AvastWin32:Malware-gen
TencentMsil.Backdoor.Bladabindi.Eegx
EmsisoftGen:Variant.Ser.Ursu.13887 (B)
ComodoMalware@#10o1d3mcsynse
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
SophosMal/Generic-S
IkarusTrojan-Dropper.MSIL.Agent
WebrootW32.Suspicious.Heur
AviraHEUR/AGEN.1208372
Antiy-AVLTrojan[Backdoor]/MSIL.Bladabindi
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftBackdoor:MSIL/Bladabindi
GDataGen:Variant.Ser.Ursu.13887
CynetMalicious (score: 99)
McAfeeArtemis!F883B7DFDE8A
MAXmalware (ai score=100)
MalwarebytesMachineLearning/Anomalous.100%
APEXMalicious
RisingMalware.Obfus/MSIL@AI.100 (RDM.MSIL:LSRM//W/CC9GP0GO8mYILw)
YandexBackdoor.Bladabindi!OuEKKhqr5EQ
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Bladabindi.DDI!tr.bdr
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ser.Ursu.13887?

Ser.Ursu.13887 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment