Malware

Ursu.286562 (B) removal tips

Malware Removal

The Ursu.286562 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.286562 (B) virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Ursu.286562 (B)?


File Info:

name: 72AEF2ED0469DC1EC439.mlw
path: /opt/CAPEv2/storage/binaries/04e87c1fbdadabe38f032b9e9eccbe83bcab379be1c40144a2c2a12e316789ac
crc32: E52EB294
md5: 72aef2ed0469dc1ec43973255af73d76
sha1: a89c05171406cd9d30ecbd0a5322e33c73dab69e
sha256: 04e87c1fbdadabe38f032b9e9eccbe83bcab379be1c40144a2c2a12e316789ac
sha512: 8ce601ea7d97f0b34bb00da5154269b11e9bb59525ab29b382e62c0c7e105b40fc0b2a56942a3086d79fe0c69b80ed41fd8ed7f467ef5f6a7b0cea6e9cba0de0
ssdeep: 384:djKDw63dGLHc/6UqmLGL7LKL6LMffq8fZkUBYH+i+lAgCjKKFpsLwpN+60cMuHqg:dM3wmS/WGdqF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T146633D03165DC6FBC92E0A3A18F341193721C39E1F268D5DA98CB01EFAA55176D43BEC
sha3_384: 67a7187d23d6f84230c0ec97b48c6486778e112208a031e32f88d508b40bcb41d3b9c073b184199c3eca2a30c19b0d4d
ep_bytes: ff250020400000000000000000000000
timestamp: 2041-09-24 19:45:53

Version Info:

Translation: 0x0000 0x04b0
Comments: Java(TM) Platform SE binary
CompanyName: Oracle Corporation
FileDescription: Java(TM) Platform SE binary
FileVersion: 8.0.3110.11
InternalName: Netflix checker.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: Netflix checker.exe
ProductName: Java(TM) Platform SE 8
ProductVersion: 8.0.3110.11
Assembly Version: 8.0.3110.11

Ursu.286562 (B) also known as:

LionicTrojan.MSIL.Injects.4!c
MicroWorld-eScanGen:Variant.Ursu.286562
FireEyeGen:Variant.Ursu.286562
ALYacGen:Variant.Ursu.286562
MalwarebytesMachineLearning/Anomalous.97%
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojan:MSIL/Injects.31ad993c
K7GWTrojan-Downloader ( 0058b1301 )
K7AntiVirusTrojan-Downloader ( 0058b1301 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.JPR
APEXMalicious
KasperskyHEUR:Trojan.MSIL.Injects.gen
BitDefenderGen:Variant.Ursu.286562
AvastWin32:KeyloggerX-gen [Trj]
Ad-AwareGen:Variant.Ursu.286562
EmsisoftGen:Variant.Ursu.286562 (B)
TrendMicroTROJ_GEN.R002C0PLB21
McAfee-GW-EditionRDN/Generic Downloader.x
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.34E705D
GridinsoftRansom.Win32.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Ursu.286562
CynetMalicious (score: 100)
AhnLab-V3Malware/Gen.Generic.C4814310
McAfeeRDN/Generic Downloader.x
TencentMsil.Trojan.Injects.Ahfa
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.JPR!tr.dldr
BitDefenderThetaGen:NN.ZemsilF.34084.em0@aiBmhFp
AVGWin32:KeyloggerX-gen [Trj]
Cybereasonmalicious.d0469d
PandaTrj/GdSda.A

How to remove Ursu.286562 (B)?

Ursu.286562 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment