Malware

Ursu.325147 removal instruction

Malware Removal

The Ursu.325147 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.325147 virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Ursu.325147?


File Info:

name: BE05261DBECA46590AAD.mlw
path: /opt/CAPEv2/storage/binaries/b5ef4940c8027c50ce0e196a322617d9135d0424a38ae7458d1dbaf47d31ae53
crc32: 8534E2EC
md5: be05261dbeca46590aadf8c7848c6af1
sha1: edb7b337b436f30e1c6666eb27cfe9e9a448b66a
sha256: b5ef4940c8027c50ce0e196a322617d9135d0424a38ae7458d1dbaf47d31ae53
sha512: 09a94b5235b8272cffa598789334462b4645a6e59273b592ed66d4f4cae5f484e9a6e37af138af7a56fbfb7d5705d2030978e56b48a92048540b171e810e79c3
ssdeep: 3072:7pnpjZMKxbGJfN8//1Y0yv4va4v6bVbLj6jX0h5F0h5kHY7HYH5gFezzJaJ:7ppqdN8//G0yNbVbLjqX0hb0hpczE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T143154FB0B2C7C5B4D41802FCF8E3E6F6117A6D28E930851B69BE7E5A7972DD20C15A0D
sha3_384: 2ecfd79afadc69ed1783efe48bb3681d4a65c2ca413f57a6be7da3b3b4d4afebae18225c94517236616f2bcc5dff5f7a
ep_bytes: ff250020400000000000000000000000
timestamp: 2064-07-20 16:07:47

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: m1
FileVersion: 1.0.0.0
InternalName: m1.exe
LegalCopyright: Copyright © 2022
LegalTrademarks:
OriginalFilename: m1.exe
ProductName: m1
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Ursu.325147 also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Ursu.4!c
MicroWorld-eScanGen:Variant.Ursu.325147
FireEyeGen:Variant.Ursu.325147
ALYacGen:Variant.Ursu.325147
CylanceUnsafe
VIPREGen:Variant.Ursu.325147
CrowdStrikewin/malicious_confidence_70% (W)
AlibabaTrojan:MSIL/Startun.e9dae942
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.MSIL.Startun.gen
BitDefenderGen:Variant.Ursu.325147
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Variant.Ursu.325147
EmsisoftGen:Variant.Ursu.325147 (B)
McAfee-GW-EditionArtemis
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Ursu.325147
AviraTR/Redcap.yzmjm
Antiy-AVLTrojan/Generic.ASMalwS.720E
MicrosoftTrojan:Win32/Wacatac.B!ml
McAfeeArtemis!BE05261DBECA
MAXmalware (ai score=89)
TrendMicro-HouseCallTROJ_GEN.R002H09HE22
RisingTrojan.Startun!8.112B9 (CLOUD)
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZemsilF.34592.2m0@aWoUf1k
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.dbeca4

How to remove Ursu.325147?

Ursu.325147 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment