Malware

Ursu.26349 removal tips

Malware Removal

The Ursu.26349 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.26349 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Queries information on disks for anti-virtualization via Device Information APIs
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Creates a slightly modified copy of itself

How to determine Ursu.26349?


File Info:

crc32: 5A10A88C
md5: b5288bf82ae6d374e1da1a4da3e77373
name: B5288BF82AE6D374E1DA1A4DA3E77373.mlw
sha1: 98c8690486692d4289e14fb62c521b29424f8875
sha256: 95d636383b52125f4f4327b75a4f1ad1fc8cdd481fc7ca8865fd3a834c665d28
sha512: ab65648c4093ce42b418e93b072b9371cdaf61dccb54841f9c3d089d20eec7cba27731b5a5d5bde377d69e5776b91f7273cd814454a28f3641299a48090dd6ec
ssdeep: 12288:PXYH8+WYLZIGwhiYmFT/bqozT6VhFxwZBH1Et03fYw:obLZIPkTqSsxwrVEug
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 2016 All rights reserved. AMD Inc.
FileVersion: 9.8.3.391
CompanyName: AMD Inc.
ProductName: LipsVested
ProductVersion: 9.8.3.391
FileDescription: Inta Kung Easier Areal Cunningham
OriginalFilename: LipsVested.exe
Translation: 0x0409 0x04b0

Ursu.26349 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0056e90d1 )
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.26349
ALYacGen:Variant.Ursu.26349
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaBackdoor:Win32/Androm.ed7587cb
K7GWTrojan ( 0056e90d1 )
Cybereasonmalicious.82ae6d
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.FNNF
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyBackdoor.Win32.Androm.opjz
BitDefenderGen:Variant.Ursu.26349
NANO-AntivirusTrojan.Win32.Androm.fhvofk
TencentWin32.Backdoor.Androm.Pdca
Ad-AwareGen:Variant.Ursu.26349
SophosMal/Generic-S
ComodoMalware@#1mix7ofvcp3xi
BitDefenderThetaGen:NN.ZexaF.34684.Ey0@a8hVRboi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Ransomware.gc
FireEyeGeneric.mg.b5288bf82ae6d374
EmsisoftGen:Variant.Ursu.26349 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1123833
eGambitUnsafe.AI_Score_99%
MicrosoftTrojanSpy:Win32/Ursnif
AegisLabTrojan.Multi.Generic.4!c
ZoneAlarmBackdoor.Win32.Androm.opjz
GDataGen:Variant.Ursu.26349
Acronissuspicious
McAfeeArtemis!B5288BF82AE6
MAXmalware (ai score=98)
VBA32BScope.TrojanRansom.Foreign
MalwarebytesMachineLearning/Anomalous.96%
PandaTrj/CI.A
TrendMicro-HouseCallPossible_HPGen-38
RisingBackdoor.Androm!8.113 (CLOUD)
YandexBackdoor.Androm!ep3EL5DPq6U
IkarusTrojan-Ransom.GandCrab
FortinetW32/Kryptik.FOQJ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ursu.26349?

Ursu.26349 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment