Malware

Ursu.139527 (file analysis)

Malware Removal

The Ursu.139527 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.139527 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup

How to determine Ursu.139527?


File Info:

crc32: BFC624B4
md5: 7f953fa033fc1e4b0abe9b1889a38db2
name: 7F953FA033FC1E4B0ABE9B1889A38DB2.mlw
sha1: ba570d94aeceb7002ef64bbc9ac26d1c8d1fa4dc
sha256: 6b8543f284eed7cf07ef40288c1bc6b197c30bca604ec1a560ffca5771d181e1
sha512: fca669d2ddc756c90fc28551ea86ee3b79397eace4fbc3cca4d2d794be152fd562889229b13ff731465e129da41d3ad5e7b41673c6b3289fce34bd1d3f7d2aea
ssdeep: 12288:DJRXrQbx+q9Gq1QlaCuV7UzhHD2RnAyK8SNX5q1goIEocng1mJIAN8VxZSva6NHZ:DLe8c5CEoztD2ib8O5GIHcnNaxZSttHn
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ursu.139527 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen7.25622
MicroWorld-eScanGen:Variant.Ursu.139527
FireEyeGeneric.mg.7f953fa033fc1e4b
McAfeeArtemis!7F953FA033FC
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 005257651 )
AlibabaTrojan:Win32/Blamon.5044b56f
K7GWTrojan ( 005257651 )
BitDefenderThetaGen:NN.ZedlaF.34590.TmOdauzKmIgi
CyrenW32/Heuristic-162!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
KasperskyTrojan.Win32.Blamon.byo
BitDefenderGen:Variant.Ursu.139527
NANO-AntivirusTrojan.Win32.Agent.eqaada
Paloaltogeneric.ml
AegisLabTrojan.Win32.Bjlog.lpqK
TencentMalware.Win32.Gencirc.1149563a
Ad-AwareGen:Variant.Ursu.139527
EmsisoftGen:Variant.Ursu.139527 (B)
ComodoBackdoor.Win32.Popwin.~IQ@ogvrk
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-R + Mal/Packer
McAfee-GW-EditionBehavesLike.Win32.Injector.bc
SophosMal/Packer
GDataGen:Variant.Ursu.139527
WebrootW32.Backdoor.Gen
MAXmalware (ai score=83)
ArcabitTrojan.Ursu.D22107
ZoneAlarmTrojan.Win32.Blamon.byo
VBA32BScope.Trojan.Wacatac
ALYacGen:Variant.Ursu.139527
ESET-NOD32a variant of Win32/Packed.BlackMoon.A potentially unwanted
RisingTrojan.Kryptik!1.B3E8 (CLASSIC)
YandexPacked/NSPack
SentinelOneDFI – Suspicious PE
AVGFileRepMalware
Qihoo-360Win32/Trojan.731

How to remove Ursu.139527?

Ursu.139527 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment