Malware

Ursu.248879 removal tips

Malware Removal

The Ursu.248879 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.248879 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Ursu.248879?


File Info:

name: CA6A40A9C2F43D2BF14E.mlw
path: /opt/CAPEv2/storage/binaries/22e0e874c265d691ea96306453d20a849127abc6c8f5f77d72ed2c59e236c215
crc32: 1484AAA9
md5: ca6a40a9c2f43d2bf14e198cde5cda55
sha1: bf43103c3384df2b1a6c3ea3deb04f56983337e2
sha256: 22e0e874c265d691ea96306453d20a849127abc6c8f5f77d72ed2c59e236c215
sha512: 7059fb162986e67915fcad8e2df00ac23bd6b55c9ff8e012bc79924e89a6dd617711217d28f892e1bbfd61d65be1e349c10f0b398e18c5da1208b5cc2821d6a1
ssdeep: 3072:pHGcJYoCPkrPjykReYtpu5jvAPcefht8baRYX2NCancRu7A+SfZEPCNIB2BMshqh:pHGcSVojyk1qjD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BD74A66275953B88F47FAF3EE23C1AA4D3F75822C747EB653EA7008C0877A85D519842
sha3_384: 1cc4a6b1dc78c8301d9a5622b04a7dd18060e90f2a809c902f60a0ac016cd50284b71de48e669736c585e075c6bf86f4
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-09-16 13:20:47

Version Info:

Translation: 0x0000 0x04b0
Comments: B
CompanyName: C
FileDescription: A
FileVersion: 1.0.0.0
InternalName: wininit.exe
LegalCopyright: E
LegalTrademarks: F
OriginalFilename: wininit.exe
ProductName: D
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Ursu.248879 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.248879
FireEyeGeneric.mg.ca6a40a9c2f43d2b
McAfeeGeneric.dyt
CylanceUnsafe
ZillyaBackdoor.SpyGate.Win32.4854
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaBackdoor:MSIL/SpyGate.922d525e
K7GWTrojan ( 004c8c941 )
K7AntiVirusTrojan ( 004c8c941 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.CXU
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.DarkComet-9811597-1
KasperskyHEUR:Backdoor.MSIL.SpyGate.gen
BitDefenderGen:Variant.Ursu.248879
NANO-AntivirusTrojan.Win32.Agent.elgxdg
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Ursu.248879
SophosMal/Generic-S
McAfee-GW-EditionGeneric.dyt
EmsisoftGen:Variant.Ursu.248879 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Ursu.248879
AviraTR/Dropper.Gen
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.281167E
MicrosoftBackdoor:MSIL/Bladabindi
CynetMalicious (score: 99)
BitDefenderThetaGen:NN.ZemsilF.34294.vq0@a4Z0Q4o
ALYacGen:Variant.Ursu.248879
TencentMsil.Backdoor.Spygate.Szli
YandexTrojan.Kryptik!a2A2yIMiqXI
IkarusTrojan-Dropper.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Kryptik.CXU!tr
AVGWin32:Malware-gen
Cybereasonmalicious.9c2f43
PandaTrj/GdSda.A

How to remove Ursu.248879?

Ursu.248879 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment