Malware

Ursu.139291 removal guide

Malware Removal

The Ursu.139291 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.139291 virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Ursu.139291?


File Info:

name: 81C84A4BDB14B560D77F.mlw
path: /opt/CAPEv2/storage/binaries/e2e197883dcf6fc1f725e3a6a1cdf91b6841c3010845d55cb8fe4d1d22d6e116
crc32: 8F07A032
md5: 81c84a4bdb14b560d77fafc1c8c9e74e
sha1: 6a7e8e0bf904f2f40e17707e64f5c369bdb7d55c
sha256: e2e197883dcf6fc1f725e3a6a1cdf91b6841c3010845d55cb8fe4d1d22d6e116
sha512: 3ef8e7a250cf6f10b958994290c05701c29aa8de95e2dc0b4a3017c378ca00f54780d418292ee19d639825a3cf7cb4f215c280e283e8e1252a1ab12baa4e95ce
ssdeep: 1536:L11JKI4fo5X69Ui33G93Yu0qMG/83LJeUnLaYakACtMI:h1J548qP3C3ijbINYakACP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16053E08533F258B4CE1ED3324A6252894330C3097A479365ACD0F6AD1D937AF7F42B62
sha3_384: 1a46ef86d550980787cc849b6457d38cf92c269cf0ef14d3720d2b3fe77610b5e4a36f1b992e362fc7f3d67c4c86435a
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-07-25 07:19:50

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: WindowsApp6
FileVersion: 1.0.0.0
InternalName: WindowsApp6.exe
LegalCopyright: Copyright © 2023
LegalTrademarks:
OriginalFilename: WindowsApp6.exe
ProductName: WindowsApp6
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Ursu.139291 also known as:

LionicTrojan.Win32.Ursu.4!c
MicroWorld-eScanGen:Variant.Ursu.139291
FireEyeGeneric.mg.81c84a4bdb14b560
McAfeeArtemis!81C84A4BDB14
MalwarebytesTrojan.Crypt.MSIL
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004c6b2c1 )
AlibabaTrojan:MSIL/Kryptik.44048e96
K7GWTrojan ( 004c6b2c1 )
Cybereasonmalicious.bdb14b
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.CMY
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Ursu.139291
NANO-AntivirusTrojan.Win32.Kryptik.jxpfrl
AvastWin32:CrypterX-gen [Trj]
TencentMsil.Trojan.Dropper.Osmw
EmsisoftGen:Variant.Ursu.139291 (B)
F-SecureTrojan.TR/Dropper.MSIL.Gen
VIPREGen:Variant.Ursu.139291
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Ursu.139291
AviraTR/Dropper.MSIL.Gen
Antiy-AVLTrojan/MSIL.Kryptik
ArcabitTrojan.Ursu.D2201B
MicrosoftTrojan:MSIL/AsyncRAT.MBCF!MTB
GoogleDetected
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.36318.dm0@ayOf3fm
ALYacGen:Variant.Ursu.139291
MAXmalware (ai score=83)
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_GEN.R014H09GP23
RisingMalware.Obfus/MSIL@AI.83 (RDM.MSIL2:koJoRylZOB1rxuuB8fqAdw)
IkarusTrojan.MSIL.Crypt
MaxSecureTrojan.Malware.73787673.susgen
FortinetMSIL/Kryptik.CMY!tr
AVGWin32:CrypterX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ursu.139291?

Ursu.139291 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment