Malware

Ursu.144460 removal

Malware Removal

The Ursu.144460 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.144460 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Ursu.144460?


File Info:

name: F01F7CF5D67594AD7BC8.mlw
path: /opt/CAPEv2/storage/binaries/949590680417ca269256de6984d1cce379a5fcafa3e8326700997e3acbe50a17
crc32: 1FC4949B
md5: f01f7cf5d67594ad7bc820d7a1a6c558
sha1: 1f1a2f148718212fa4870b23656f829ec99a5ebd
sha256: 949590680417ca269256de6984d1cce379a5fcafa3e8326700997e3acbe50a17
sha512: 7c884193e51789ff91d4015e64c51dbbdd904bd2fac45eaba651c1ad81c6d3de23b8d02446259fefc407d7fa7ee1518e5cddf16109139b23afd210888520cf96
ssdeep: 12288:gjL+EI8nXsEDo34LGQtVkNZUmryiTUY0lXU4+g03I2U5KBBr:+LvI8ncEEU38dry+UY01UjjEA
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E555E86729D25128400AF3220BA80B3FD9D39AD7B71A9EDCC20DCD9795F4561AD28FCD
sha3_384: 8282d5640e2af23b54ea8266a94dd8dac879f09ad257b7073d53da80e8a65bfcf38f98f88bbbd224c46546004bb740cd
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-01-30 00:26:31

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: File.exe
LegalCopyright:
OriginalFilename: File.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Ursu.144460 also known as:

LionicTrojan.MSIL.Bladabindi.m!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.144460
FireEyeGeneric.mg.f01f7cf5d67594ad
ALYacGen:Variant.Ursu.144460
CylanceUnsafe
SangforBackdoor.MSIL.Bladabindi.gen
K7AntiVirusTrojan ( 0058da821 )
AlibabaTrojan:Win32/runner.ali1000123
K7GWTrojan ( 0058da821 )
Cybereasonmalicious.5d6759
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.ADJL
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
BitDefenderGen:Variant.Ursu.144460
AvastWin32:TrojanX-gen [Trj]
TencentMsil.Backdoor.Bladabindi.Dypr
EmsisoftTrojan.Generic (A)
DrWebTrojan.DownLoader43.45531
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan.MSIL.Crypt
AviraHEUR/AGEN.1122591
Antiy-AVLTrojan/Generic.ASMalwS.351D080
GridinsoftRansom.Win32.Bladabindi.sa
MicrosoftBackdoor:MSIL/Bladabindi.BI
ZoneAlarmHEUR:Backdoor.MSIL.Bladabindi.gen
GDataGen:Variant.Ursu.144460
AhnLab-V3Trojan/Win.Generic.C4670529
McAfeeArtemis!F01F7CF5D675
MAXmalware (ai score=82)
VBA32TScope.Trojan.MSIL
TrendMicro-HouseCallTROJ_GEN.R014H0CB222
RisingTrojan.Generic/MSIL@AI.98 (RDM.MSIL:7wSg9FF84RS+9XrSAC+I3g)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.ADJL!tr
BitDefenderThetaGen:NN.ZemsilF.34182.on0@a8D2fIi
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Ursu.144460?

Ursu.144460 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment