Malware

How to remove “Ursu.240663”?

Malware Removal

The Ursu.240663 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.240663 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Collects and encrypts information about the computer likely to send to C2 server
  • Attempts to interact with an Alternate Data Stream (ADS)

How to determine Ursu.240663?


File Info:

name: C488BD336FE6596B1EDE.mlw
path: /opt/CAPEv2/storage/binaries/55d684373ac1d36c933b3ec512c5844d2e528325f84ff672795bf334b531ef30
crc32: B6264357
md5: c488bd336fe6596b1edeb37d8f40d713
sha1: f9dd1e19d19adebc85db724e3ae4ba850ae3bf2f
sha256: 55d684373ac1d36c933b3ec512c5844d2e528325f84ff672795bf334b531ef30
sha512: 41ed4917b36395ecda2cacb7e24ea9f76e7bd08c5acf21fa74ad319a8168c01e09420ec4f705addfa9f76df7474adea18ae8753a6418325cfd712d09dce421c3
ssdeep: 6144:xbcjvIopa9oEg0uAdZ9Yj6m616WF+lP2Ng059GLk+BX7MU/+zb4byKTJQIS2TnEG:+c44xbZdZ9Yj6D1gfRMU/ZxStmQM
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F0F44C1337968642E9681BB2C0DBA14053F06A47633BD70EFFE627DD1C87756AA8720D
sha3_384: 26fdccd991089f34b480753e75c8db4575e15ab943268d0d1a20c575be06a9a8e24ab966827297a7aea6a61d4783468e
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-06-21 18:04:52

Version Info:

Translation: 0x0000 0x04b0
FileDescription: Dxc
FileVersion: 1.0.0.0
InternalName: Dxc.exe
LegalCopyright: Copyright © 2018
OriginalFilename: Dxc.exe
ProductName: Dxc
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Ursu.240663 also known as:

LionicTrojan.Win32.Generic.4!c
DrWebTrojan.DownLoader26.42192
MicroWorld-eScanGen:Variant.Ursu.240663
FireEyeGeneric.mg.c488bd336fe6596b
McAfeePacked-SD!C488BD336FE6
CylanceUnsafe
SangforTrojan.MSIL.AgentTesla.KM
K7AntiVirusTrojan ( 004d53931 )
AlibabaTrojan:MSIL/Kryptik.fd9c61e7
K7GWTrojan ( 004d53931 )
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZemsilF.34084.Vq0@aWgO@Gd
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.DZJ
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Ransom.Win32.Agent.gen
BitDefenderGen:Variant.Ursu.240663
NANO-AntivirusTrojan.Win32.Kryptik.fekuit
AvastWin32:Malware-gen
TencentWin32.Trojan.Agent.Sxxw
Ad-AwareGen:Variant.Ursu.240663
SophosMal/Generic-S
ComodoMalware@#34jy4usx5kq5d
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPacked-SD!C488BD336FE6
EmsisoftGen:Variant.Ursu.240663 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.MSIL.Gen
Antiy-AVLTrojan/Generic.ASMalwS.26BD002
MicrosoftBackdoor:MSIL/Bladabindi!rfn
GDataGen:Variant.Ursu.240663
CynetMalicious (score: 99)
VBA32TScope.Trojan.MSIL
ALYacGen:Variant.Ursu.240663
MAXmalware (ai score=95)
YandexTrojan.Kryptik!KURujfzCcTM
IkarusBackdoor.MSIL.Bladabindi
FortinetMSIL/Kryptik.MQN!tr
AVGWin32:Malware-gen
Cybereasonmalicious.36fe65
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Ursu.240663?

Ursu.240663 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment