Malware

What is “Ursu.262836”?

Malware Removal

The Ursu.262836 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.262836 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to remove evidence of file being downloaded from the Internet
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
javadllhost.zapto.org

How to determine Ursu.262836?


File Info:

crc32: 1A0D7F48
md5: ee2e5f082d8d22c466633dd953115b5f
name: EE2E5F082D8D22C466633DD953115B5F.mlw
sha1: 719979fb01aba3c443fc49962526179c9bb1e172
sha256: 2660503a42c960a1097290d6070ffced21a9eed75735d201a629aa5a925e1a2e
sha512: 33107d4c3fc146844a65fac4b113f684d06a9626787792516b812664f6d13fd04554eef2b292409a4743798cc5c11b124e4241177e89d0cd8aeeecb9548ceab0
ssdeep: 6144:96afPGbgDfWg3TDrjjM9pCpyqPqEvwqDqgpB8QyVtjXX8YqkAo3jA:9r0g3rApCoqSEvtDdB8Qyjn8YqW
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: (c) 2004-2007 Piston Software
InternalName: Pistonsoft BPM Detector
FileVersion: 1.0.0.0
CompanyName: Piston Software
LegalTrademarks: (tm) Pistonsoft BPM Detector
Comments: Pistonsoft BPM Detector - Count Song's Beats per Minute Automatically
ProductName: Pistonsoft BPM Detector
ProductVersion: 1.0.0.0
FileDescription: Pistonsoft BPM Detector
OriginalFilename: BPMDetector.exe
Translation: 0x0409 0x04e4

Ursu.262836 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.276
ClamAVWin.Dropper.Nanocore-9903300-0
ALYacGen:Variant.Ursu.262836
CylanceUnsafe
ZillyaTrojan.GenericKD.Win32.198456
SangforVirus.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:MSIL/MalwareX.9121f994
K7GWTrojan ( 0052a44b1 )
K7AntiVirusTrojan ( 0052a44b1 )
CyrenW32/MSIL_Kryptik.BVZ.gen!Eldorado
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.DNB
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
CynetMalicious (score: 100)
KasperskyTrojan.MSIL.Crypt.gwhb
BitDefenderGen:Variant.Ursu.262836
NANO-AntivirusTrojan.Win32.Generic.ffyaic
MicroWorld-eScanGen:Variant.Ursu.262836
TencentWin32.Trojan.Inject.Auto
Ad-AwareGen:Variant.Ursu.262836
BitDefenderThetaGen:NN.ZemsilF.34236.xm1@ay0v1Xic
TrendMicroBackdoor.MSIL.ASDROP.SMZSM
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.ee2e5f082d8d22c4
EmsisoftGen:Variant.Ursu.262836 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1104058
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.272265E
MicrosoftHackTool:MSIL/Boilod.A
ArcabitTrojan.Ursu.D402B4
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
GDataGen:Variant.Ursu.262836
McAfeeArtemis!EE2E5F082D8D
MAXmalware (ai score=100)
MalwarebytesTrojan.Dropper
PandaTrj/GdSda.A
TrendMicro-HouseCallBackdoor.MSIL.ASDROP.SMZSM
YandexTrojan.Crypt!SJmyXbXy3l4
IkarusTrojan-Dropper.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/CoinMiner.SHS!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Ursu.262836?

Ursu.262836 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment