Malware

Ser.Ursu.7236 removal guide

Malware Removal

The Ser.Ursu.7236 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Ursu.7236 virus can do?

  • Reads data out of its own binary image
  • Unconventionial binary language: Portuguese (Brazil)
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Ser.Ursu.7236?


File Info:

name: B482F7A45186F6974711.mlw
path: /opt/CAPEv2/storage/binaries/11c4fe4d84ae3330817d1e22a6d43c8593c63dc0a9000dd08f833e0035956c36
crc32: 8B603B7C
md5: b482f7a45186f69747115bb8e97551e6
sha1: 21655345483484d15b26853852caef543513f9fb
sha256: 11c4fe4d84ae3330817d1e22a6d43c8593c63dc0a9000dd08f833e0035956c36
sha512: c6901fdb2af62e0796aab27031cc8361e63c6244a030659500ad0f49ff1a44edb3fda5f3bc9eed8cd49aa2043654a92a800de8696ccae86c5a52ac6cc4219fae
ssdeep: 12288:XUzmqOeHkziCiqh5IlBdl8myIWiOavGyIWS+amASi6V0h21OQyYd4ls9oqNiK4P1:XUCqwi10IlgSi521qPslzbjqelQrnp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C3253A3B778E9936DC3258BC4D8FE1A0A45A36742C189E93F7D09F4D5E34181372A98B
sha3_384: 3a486958a5caaf0833ac85d9cae7b5e6b95b0078e482153a8d58dd2333600ece7e027c843ba646981e5a3f842ce7a0ee
ep_bytes: 558bec83c4f05356b87c6c4e00e86601
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName:
FileDescription:
FileVersion: 1.0.0.37
InternalName:
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Translation: 0x0416 0x04e4

Ser.Ursu.7236 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Blocker.ts8p
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.b482f7a45186f697
CAT-QuickHealTrojan.Dorv.9812
McAfeePWS-Banker.gen.ez
CylanceUnsafe
VIPREGen:Variant.Ser.Ursu.7236
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 0026b47a1 )
BitDefenderGen:Variant.Ser.Ursu.7236
K7GWSpyware ( 0026b47a1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Generic.CLMX
CyrenW32/Banker.V.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Banker.WGA
APEXMalicious
ClamAVWin.Trojan.Netmail-9844910-0
KasperskyTrojan-Ransom.Win32.Blocker.kkoq
AlibabaRansom:Win32/Blocker.0466c198
NANO-AntivirusTrojan.Win32.FakeAV.drrvw
MicroWorld-eScanGen:Variant.Ser.Ursu.7236
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Blocker.Hjgl
Ad-AwareGen:Variant.Ser.Ursu.7236
SophosML/PE-A + Troj/Banker-GYO
ComodoTrojWare.Win32.Spy.Banker.VIS@8ekceg
DrWebTrojan.DownLoader4.51703
ZillyaTrojan.FakeAV.Win32.109581
TrendMicroRansom_Blocker.R002C0DJE22
McAfee-GW-EditionBehavesLike.Win32.PWSBanker.fh
EmsisoftGen:Variant.Ser.Ursu.7236 (B)
SentinelOneStatic AI – Suspicious PE
AviraDR/Delphi.Gen
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.55
MicrosoftTrojan:Win32/Dorv.B!rfn
GDataWin32.Trojan-Stealer.Banker.AK
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.C134638
VBA32BScope.Trojan.Downloader
ALYacGen:Variant.Ser.Ursu.7236
TACHYONTrojan/W32.DP-Agent.1044992.C
MalwarebytesMalware.AI.1216204204
TrendMicro-HouseCallRansom_Blocker.R002C0DJE22
RisingRansom.Agent!8.6B7 (TFE:5:Ku0xTvM8GaG)
YandexTrojan.FakeAV!WsJ4kBJx68o
IkarusTrojan-Banker.Win32.Delf
FortinetW32/Banker.WGA!tr
BitDefenderThetaGen:NN.ZelphiF.34726.@G0@ai1z35iG
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.45186f
PandaGeneric Malware

How to remove Ser.Ursu.7236?

Ser.Ursu.7236 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment