Malware

Ursu.229943 (file analysis)

Malware Removal

The Ursu.229943 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.229943 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering

How to determine Ursu.229943?


File Info:

name: 02B6C4234B5D1FB77880.mlw
path: /opt/CAPEv2/storage/binaries/18fe9243ef9bbb0cc75cc9a679badfd8d0ad07207d68845a5a2250f1e9eb8a69
crc32: 67BAAFAC
md5: 02b6c4234b5d1fb778802a3a9c8c9001
sha1: baf08d79de95182b95f573efbd84168470d4240b
sha256: 18fe9243ef9bbb0cc75cc9a679badfd8d0ad07207d68845a5a2250f1e9eb8a69
sha512: 468f93c3982cf90ddcc8334a09c6594c535f31e65eab787fcb93d51157bdbe377544a3f3f22c8017f0275161ff8230b51ccc3db0be187f785adf1124fafe891a
ssdeep: 24576:ZCmwhf7hrcKdzWDAihVtmL83RfZ59C1iXNigNps7Ossljsjobg/DTd9xUop9WrYr:QmwhDlc9JLb9BXEgNy7OhCTb6onW+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15D858D22B2818433D1176A359D1BD3B55926BF202E2858873BF53F4E7F36B827835297
sha3_384: 3fb5bd3dcc797cae497c827d3f4ac1a198c096247683834a7bdf205e88b3e51c69b2516c44fbf9ac12487fdc04ce10b1
ep_bytes: 558bec83c4f053b8c0815400e8c3e3eb
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Ursu.229943 also known as:

LionicRiskware.Win32.Ursu.1!c
MicroWorld-eScanGen:Variant.Ursu.229943
FireEyeGen:Variant.Ursu.229943
McAfeeArtemis!02B6C4234B5D
Cylanceunsafe
Cybereasonmalicious.34b5d1
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Ursu.229943
EmsisoftGen:Variant.Ursu.229943 (B)
VIPREGen:Variant.Ursu.229943
McAfee-GW-EditionBehavesLike.Win32.BadFile.th
Trapminesuspicious.low.ml.score
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Ursu.229943
ArcabitTrojan.Ursu.D38237
MicrosoftTrojan:Win32/Zpevdo.A
ALYacGen:Variant.Ursu.229943
MAXmalware (ai score=86)
MalwarebytesGeneric.Malware/Suspicious
RisingTrojan.Zpevdo!8.F912 (CLOUD)
MaxSecureTrojan.Malware.73720805.susgen
FortinetPossibleThreat.MU
DeepInstinctMALICIOUS

How to remove Ursu.229943?

Ursu.229943 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment