Malware

Ursu.22016 removal instruction

Malware Removal

The Ursu.22016 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.22016 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself

How to determine Ursu.22016?


File Info:

crc32: 7F5D8647
md5: b2b977891cb5edc89069eb1bec31768f
name: B2B977891CB5EDC89069EB1BEC31768F.mlw
sha1: 985e90995f2990b0646599d563defbb5d1deb5d3
sha256: 8cca737aac7bc7bf3a022174d756ee0488bdd66575bd1b40148b5d21e8dc3746
sha512: 73009a51dc0c4a9c88687ebb7dabac3ffd48d1a6b8fe96ac34ac50526184f8b7fcfcf47ccec77cc5a47795be5fc08fc8b22a7f39e8a491be5c62be87a0268fa7
ssdeep: 6144:Eap0vp2b2Ink/dih4dnJ+DUxrqYvT4jPHFPyVbhZcL9yIMuGkYY+oE5PYgw:EaSR2b2Inf4BA8F7YidZYoIMuGAzENt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 2015
InternalName: Wondershare
FileVersion: 3.8.0.3
LegalTrademarks: Wondershare
ProductName: Wondershare DVD Creator Crack UZ1
ProductVersion: 3.8.0.3
FileDescription: Wondershare DVD Creator Crack UZ1
OriginalFilename: DVDCreator.exe
Translation: 0x0409 0x04b0

Ursu.22016 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0056e8fe1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.18284
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.22016
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 0056e8fe1 )
Cybereasonmalicious.91cb5e
SymantecTrojan Horse
ESET-NOD32a variant of Win32/Kryptik.DQUU
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Foreign.ntlx
BitDefenderGen:Variant.Ursu.22016
NANO-AntivirusTrojan.Win32.Stealer.fhxjhp
MicroWorld-eScanGen:Variant.Ursu.22016
TencentWin32.Trojan.Foreign.Pfjd
Ad-AwareGen:Variant.Ursu.22016
SophosMal/Generic-S
ComodoMalware@#2in358twi9itx
BitDefenderThetaGen:NN.ZexaF.34670.yy0@aiyeImii
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPLOCKY.SME1
McAfee-GW-EditionBehavesLike.Win32.Dropper.fc
FireEyeGeneric.mg.b2b977891cb5edc8
EmsisoftGen:Variant.Ursu.22016 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1100583
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.Ursu.D5600
AegisLabTrojan.Win32.Generic.4!c
GDataGen:Variant.Ursu.22016
Acronissuspicious
McAfeeArtemis!B2B977891CB5
MAXmalware (ai score=95)
VBA32BScope.Trojan.Yakes
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/CI.A
TrendMicro-HouseCallRansom_HPLOCKY.SME1
RisingRansom.Foreign!8.292 (CLOUD)
IkarusTrojan-Ransom.GandCrab
FortinetW32/Kryptik.FNHW!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.155

How to remove Ursu.22016?

Ursu.22016 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment