Malware

Ursu.318249 malicious file

Malware Removal

The Ursu.318249 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.318249 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Anomalous binary characteristics

How to determine Ursu.318249?


File Info:

name: 86D36A7096862D59679E.mlw
path: /opt/CAPEv2/storage/binaries/556396a10311a9e75d38c857eaca55f4a8a72a4b3b2a4dd6266192962559fb12
crc32: D70F2F37
md5: 86d36a7096862d59679e4dde8ba1294b
sha1: 9ab1117739ac47ce1c0b81825ea7f5eeec598765
sha256: 556396a10311a9e75d38c857eaca55f4a8a72a4b3b2a4dd6266192962559fb12
sha512: e19bf0fba89a661bcf3808b3493b32be8224ac64b0c8cfa093112e38afbee8936308acc6e1a6ef00f7b3eea421045959c9b1a3bd5385757e3964fefe6ca90ad8
ssdeep: 3072:8Pv0vKx6SuO4yK5AMcSrGP4WHdtT4BsUvKkpS7gno2z1N1LRIAFe:8PMvKx6Suvt+JALUPT4d47gomNXIAw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A7F3296E77C5F73AD00495BA2A58469C889FF83324216C07E3C5574BB766C8BE722327
sha3_384: da05326d4da0ff6a65539ccc2d3c446d9f41f6c3d283db8bab749fc00b6785051ad7e3209af5fb8ce05325947fbd6667
ep_bytes: 68a41d4000e8eeffffff000000000000
timestamp: 2011-05-06 10:31:35

Version Info:

CompanyName: ICQ, LLC.
FileDescription: ICQ
FileVersion: 7.5.0.5242
InternalName: ICQ
LegalCopyright: Copyright (c) 1998-2010 ICQ, LLC.
LegalTrademarks:
OriginalFilename: ICQ.exe
ProductName: ICQ
ProductVersion: 7.5.0.5242
DistId: 30012
Translation: 0x0409 0x04b0

Ursu.318249 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zbot.lmZ1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.318249
FireEyeGeneric.mg.86d36a7096862d59
ALYacGen:Variant.Ursu.318249
AlibabaWorm:Win32/VBKrypt.12323667
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZevbaF.34796.km1@ayk7bhdi
VirITTrojan.Win32.Generic.ANSE
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/AutoRun.VB.ANQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.VBKrypt.cyhi
BitDefenderGen:Variant.Ursu.318249
NANO-AntivirusTrojan.Win32.VBKrypt.dbrqs
TencentWin32.Trojan.Vbkrypt.Vwhl
Ad-AwareGen:Variant.Ursu.318249
SophosMal/Generic-S
ComodoMalware@#2uj2ps7rm7dqr
DrWebTrojan.VbCrypt.23
VIPREGen:Variant.Ursu.318249
McAfee-GW-EditionBehavesLike.Win32.Trojan.ch
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Ursu.318249 (B)
IkarusTrojan.Win32.Llac
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.VBKrypt
KingsoftWin32.Troj.VBKrypt.cy.(kcloud)
ArcabitTrojan.Ursu.D4DB29
ZoneAlarmTrojan.Win32.VBKrypt.cyhi
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.VBKrypt.R19594
Acronissuspicious
McAfeePWS-Zbot.gen.awr
VBA32Malware-Cryptor.VB.gen.1
CylanceUnsafe
RisingMalware.Undefined!8.C (TFE:3:rzv5tMpE9iJ)
YandexTrojan.GenAsa!5jJB5gcKvPw
SentinelOneStatic AI – Malicious PE
Cybereasonmalicious.096862
PandaGeneric Malware

How to remove Ursu.318249?

Ursu.318249 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment