Malware

About “Ursu.209023” infection

Malware Removal

The Ursu.209023 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.209023 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Czech
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Deletes executed files from disk
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Ursu.209023?


File Info:

name: F890D6A77E3E07A720B9.mlw
path: /opt/CAPEv2/storage/binaries/c67f752fe0a19ea2e55624f9a885696d1d690ddf06040de0f8d5346aef124819
crc32: E46E56BB
md5: f890d6a77e3e07a720b98ba133de1b16
sha1: 8adc768d264ff91b2018cff7fad9a199ae37fe7c
sha256: c67f752fe0a19ea2e55624f9a885696d1d690ddf06040de0f8d5346aef124819
sha512: 24ef5b0802ffef6cb5ecc4d325f4e4637369bb3cb3082028d47f100bcc753714aa75722015ca693b69a110931d24b786b8719bd38b1e9d633c7d564e1157d84d
ssdeep: 24576:EMPJkdV4K3wQ7BaWnBCq2Fz1HHjh8nX2btIZdsOzbtIZ7:EMPJIV4al7BaWnt2Fz1HDh8mbOzb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A955F112BA84A826D8261FB41965E7740236BE507D30D65E7AFABF4F3F3B1C64E10391
sha3_384: 9f46595dff30b8b47836d9a7c379a06a31c0a97a3280f94fdc18a2c6cab6560d9a0c8337ba958d4891ba59ccc807bdcb
ep_bytes: 558becb90d0000006a006a004975f951
timestamp: 1992-06-19 22:22:17

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Kletek MAHO
FileDescription: RahmatMR
ProductName: Regen auto 1.2.42.13
FileVersion: 1.00
ProductVersion: 1.00
InternalName: Malming
OriginalFilename: Malming.exe

Ursu.209023 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Ursu.209023
ClamAVWin.Dropper.Cloud-6605913-0
FireEyeGeneric.mg.f890d6a77e3e07a7
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Packed.Win32.88330
SangforSuspicious.Win32.Save.ins
Cybereasonmalicious.d264ff
ArcabitTrojan.Ursu.D3307F [many]
Elasticmalicious (high confidence)
ESET-NOD32multiple detections
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.209023
NANO-AntivirusTrojan.Win32.Agent.pfbvq
AvastWAT:Blacked-E
F-SecureHeuristic.HEUR/AGEN.1300357
VIPREGen:Variant.Ursu.209023
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Ursu.209023 (B)
IkarusTrojan.Win32.Vapsup
JiangminHeur:Trojan/InjectDll
GoogleDetected
AviraHEUR/AGEN.1300357
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.996
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ursu.209023 (2x)
VaristW32/Agent.NG.gen!Eldorado
VBA32TScope.Malware-Cryptor.SB
ALYacGen:Variant.Ursu.209023
MAXmalware (ai score=84)
Cylanceunsafe
RisingPUF.Agent!1.B0FE (CLASSIC)
YandexTrojan.GenAsa!ZeqaUIrvc7Q
BitDefenderThetaGen:NN.ZedlaF.36792.LG4@ailZQ5fi
AVGWAT:Blacked-E
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Ursu.209023?

Ursu.209023 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment