Malware

Ursu.156786 (B) removal guide

Malware Removal

The Ursu.156786 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.156786 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Operates on local firewall’s policies and settings

How to determine Ursu.156786 (B)?


File Info:

name: EA938476AA4C45AF413C.mlw
path: /opt/CAPEv2/storage/binaries/2c8809e4bf4f8b575fdd0ac8f642b24a1e1ab0c7e52cdff8cc02a76744811e1c
crc32: E82F7B48
md5: ea938476aa4c45af413c59e6b618040d
sha1: 160dcfbae1a310224905d9c15e960fcb42490508
sha256: 2c8809e4bf4f8b575fdd0ac8f642b24a1e1ab0c7e52cdff8cc02a76744811e1c
sha512: bb88d5f21848f3f36abb37d7194728c3b62a10aee40c5cbcc46618ca926802bdb14d4e43d723c100a6a28893d173d578507327ee265a0abb37b17968a2372657
ssdeep: 6144:SV973rKdSZOpyu/jOVjNEyxiUgwwrGXgRoy:mRGd0u/jSukg
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A3641933EA50A01EF55281B098B6913E59177CB305D87D03B385AE082575A93BEFAF1F
sha3_384: 59dbc0dcfbc1f0d4286fab5395fc0473a821782a11af47919aee3f5ea86d8f04e1a866eb9c566892179fb561db1b4064
ep_bytes: 6880684000e8f0ffffff000078000000
timestamp: 2022-08-14 17:46:55

Version Info:

Translation: 0x0409 0x04b0
CompanyName: TerminalDiscoveryServices
FileDescription: COM
LegalCopyright: COM
LegalTrademarks: COM
ProductName: COM
FileVersion: 1.02
ProductVersion: 1.02
InternalName: winsyst32
OriginalFilename: winsyst32.exe

Ursu.156786 (B) also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ursu.4!c
Elasticmalicious (high confidence)
DrWebBACKDOOR.Trojan
MicroWorld-eScanGen:Variant.Ursu.156786
ClamAVWin.Malware.Ursu-9883073-0
FireEyeGeneric.mg.ea938476aa4c45af
ALYacGen:Variant.Ursu.156786
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.vb
AlibabaTrojanSpy:Win32/WinSpy.6a9ed74f
K7GWSpyware ( 000038d81 )
BitDefenderThetaGen:NN.ZevbaF.36350.tm0@aKlNgmpi
CyrenW32/Hupigon.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.WinSpy
APEXMalicious
CynetMalicious (score: 99)
BitDefenderGen:Variant.Ursu.156786
AvastWin32:TrojanX-gen [Trj]
RisingSpyware.WinSpy!8.1AA (TFE:5:xm8bfsCOczF)
EmsisoftGen:Variant.Ursu.156786 (B)
F-SecureTrojan.TR/Spy.Winspy.gufqm
VIPREGen:Variant.Ursu.156786
McAfee-GW-EditionBehavesLike.Win32.BadFile.fm
SophosMal/Generic-S
Ikarusnot-a-virus:Monitor.Win32.WinSpy
GDataGen:Variant.Ursu.156786
AviraTR/Spy.Winspy.gufqm
MAXmalware (ai score=84)
Antiy-AVLTrojan[Spy]/Win32.WinSpy
ArcabitTrojan.Ursu.D26472
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
McAfeeArtemis!EA938476AA4C
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H09H923
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/WinSpy
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS

How to remove Ursu.156786 (B)?

Ursu.156786 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment