Malware

What is “Ursu.112930”?

Malware Removal

The Ursu.112930 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.112930 virus can do?

  • .NET file is packed/obfuscated with SmartAssembly
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Ursu.112930?


File Info:

name: C4176DB4BBD31FFC7862.mlw
path: /opt/CAPEv2/storage/binaries/20bf78890b26022db3095ecb2eb5a21957a5f64c2fe89856e39f3d9463d3ddaf
crc32: 95D2879A
md5: c4176db4bbd31ffc7862d23a4a6d5c5d
sha1: 0b9a6b63559bd78d730c1d4d8d4429f9b1711a94
sha256: 20bf78890b26022db3095ecb2eb5a21957a5f64c2fe89856e39f3d9463d3ddaf
sha512: 797091be25e6f7bf8ac8cd15deb4889b882f52f56c35f60448a183dc778e62ea04a117078179ddd28b30df1b9065337d62e38b9295fcfa315850c06e93fb6e9d
ssdeep: 12288:XgR1WUJhEfR9wDs0Rqdw5DP6Ai3Pegy9OPLc8nWYpoPA1/5:Tvwz8MDPY3Fy9OQXofx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19AC4F75BFA445F7BC12E5A33C4E3AC7C82D4C96E1B42E71FD0F8065D1A223EC5A0A959
sha3_384: 1615e98145b99d07b015e2a11f78804d9e070ca42e767f0dcd639273a0b5b9f411126a5262bcbebb3bf0778b89481c93
ep_bytes: ff250020400000000000000000000000
timestamp: 2013-07-17 15:27:34

Version Info:

0: [No Data]

Ursu.112930 also known as:

BkavW32.AIDetectNet.01
MicroWorld-eScanGen:Variant.Ursu.112930
FireEyeGeneric.mg.c4176db4bbd31ffc
McAfeeArtemis!C4176DB4BBD3
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
BitDefenderGen:Variant.Ursu.112930
K7GWTrojan ( 700000121 )
Cybereasonmalicious.4bbd31
BaiduMSIL.Backdoor.Bladabindi.a
CyrenW32/Trojan.FDS.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Bladabindi.AH
CynetMalicious (score: 99)
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Gen8.cbyhqj
RisingBackdoor.Bladabindi!1.9DE6 (CLASSIC)
Ad-AwareGen:Variant.Ursu.112930
SophosMal/Generic-S
ComodoTrojWare.MSIL.Disfa.A@56xb79
DrWebTrojan.DownLoader9.61746
VIPREGen:Variant.Ursu.112930
McAfee-GW-EditionBehavesLike.Win32.Generic.hm
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Ursu.112930 (B)
IkarusTrojan.Msil
AviraTR/Spy.Gen8
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.24D
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftBackdoor:MSIL/Bladabindi.AA
GDataGen:Variant.Ursu.112930
GoogleDetected
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.34682.JmW@ailMmCb
ALYacGen:Variant.Ursu.112930
PandaGeneric Malware
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Bbindi.W!tr
AVGMSIL:Bladabindi-IT [Wrm]
AvastMSIL:Bladabindi-IT [Wrm]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ursu.112930?

Ursu.112930 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment