Malware

How to remove “Ursu.321313”?

Malware Removal

The Ursu.321313 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.321313 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Ursu.321313?


File Info:

name: 7CE9D5EF7726031445CC.mlw
path: /opt/CAPEv2/storage/binaries/cbe4dbee4d3590e8d80286dcd1ea20936c72171dc3875051455ea8f355591def
crc32: A2104743
md5: 7ce9d5ef7726031445ccbada9e6b5bb3
sha1: 25e276188188aed34541f740a7a7c459d18995c7
sha256: cbe4dbee4d3590e8d80286dcd1ea20936c72171dc3875051455ea8f355591def
sha512: ae2d2604368ec3716c85c079450bb18ae24f18475accce433e16089fbe7fa0a1be2c9d1fa502eebb1be566d0bb7a8df82c2aec0722e406973ba2f747333fcaa4
ssdeep: 3072:lcTkhf31CN27iK5riVDobagp+CsvjZw+HqFXYzQDehBVGjxZT4rtjWwog9JJSW:Sgwk7x5rtO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T133D36B0161445ADED895327CC4EA2CBC63EAFDFE9A711769C3E078CA1BBE3B15E41148
sha3_384: 1ad3af73aebab9c1314a4ba5e2aa3ce0b8534bdaf640fde79b0beac23861423bab2875c966dcb46ce2d8d2a095a5d74d
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-12-07 06:43:14

Version Info:

Translation: 0x0000 0x04b0
CompanyName: Nishant Sivakumar
FileDescription: TypeDescriptionProviderDemo
FileVersion: 5.66.0.7716
InternalName: Crypted.exe
LegalCopyright: Copyright © 2008
OriginalFilename: Crypted.exe
ProductName: TypeDescriptionProviderDemo
ProductVersion: 5.66.0.7716
Assembly Version: 0.0.0.0

Ursu.321313 also known as:

Elasticmalicious (high confidence)
ClamAVWin.Packed.Razy-9863149-0
CAT-QuickHealBackdoor.MsilFC.S23216835
ALYacGen:Variant.Ursu.321313
MalwarebytesTrojan.MalPack
K7AntiVirusTrojan ( 004dcb4e1 )
BitDefenderGen:Variant.Ursu.321313
K7GWTrojan ( 004dcb4e1 )
Cybereasonmalicious.f77260
CyrenW32/MSIL_Troj.UX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.XBC
APEXMalicious
AvastWin32:RATX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.MSIL.Crysan.gen
MicroWorld-eScanGen:Variant.Ursu.321313
Ad-AwareGen:Variant.Ursu.321313
EmsisoftTrojan-Spy.Agent (A)
DrWebTrojan.DownLoader33.58755
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.7ce9d5ef77260314
SophosMal/DotNet-C
IkarusTrojan.MSIL.Krypt
GDataGen:Variant.Ursu.321313
AviraTR/Dropper.MSIL.Gen
MAXmalware (ai score=89)
ArcabitTrojan.Ursu.D4E721
MicrosoftBackdoor:MSIL/Bladabindi.RKC!MTB
AhnLab-V3Trojan/Win32.Korat.R341547
McAfeePWS-FCRS!7CE9D5EF7726
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/CoinMiner.ESXT!tr
BitDefenderThetaGen:NN.ZemsilF.34062.im0@aWUV1Uf
AVGWin32:RATX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Ursu.321313?

Ursu.321313 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment