Malware

About “Ursu.332044” infection

Malware Removal

The Ursu.332044 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.332044 virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Ursu.332044?


File Info:

name: 62F640250A8E1D7D5B6C.mlw
path: /opt/CAPEv2/storage/binaries/5de5f22909a21768fa1d58e957174a64594202edf7282ec8416d435831f65d52
crc32: 82AC98DB
md5: 62f640250a8e1d7d5b6c7cd204ae9520
sha1: 79858e6c75448e1ee1928002c9ee80392ab1e75e
sha256: 5de5f22909a21768fa1d58e957174a64594202edf7282ec8416d435831f65d52
sha512: 06c34675fc79667b330dc4cb5d0cdac9181981de962744339a9e399266a5ed363b18150c00ecdb6cea305d3c374134a0bc6e6780553baa55f9c70e6dbddb200b
ssdeep: 3072:d9fqN6GW0TejsKi0ptXPqmiH7sJrQhKzzBQ4uj/:+NVKFi0mHQz93u
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T139548F71D0629BF5F5F086ED6EF41C704D7028A3CAACE177B0CF9A9E6089B7059D84A4
sha3_384: a1135d87e1ea4687611e89bd382a5dc8e03a9a886a26ddb4a9f69d1db168b485d7c119da4d06f4fdf0536b2f4ed3ddf6
ep_bytes: ff250020400000000000000000000000
timestamp: 2062-05-18 20:12:11

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: fud
FileVersion: 1.0.0.0
InternalName: fud.exe
LegalCopyright: Copyright © 2019
LegalTrademarks:
OriginalFilename: fud.exe
ProductName: fud
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Ursu.332044 also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.332044
McAfeeArtemis!62F640250A8E
CylanceUnsafe
VIPREGen:Variant.Ursu.332044
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Kryptik.ad8a8cb0
K7GWTrojan ( 004c9fe61 )
K7AntiVirusTrojan ( 004c9fe61 )
CyrenW32/MSIL_Kryptik.AWF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.EKX
APEXMalicious
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.332044
NANO-AntivirusTrojan.Win32.Kryptik.fpzske
AvastWin32:Trojan-gen
TencentWin32.Trojan.Generic.Iajl
Ad-AwareGen:Variant.Ursu.332044
EmsisoftGen:Variant.Ursu.332044 (B)
ComodoMalware@#28f1t49wmaer5
DrWebTrojan.PackedNET.195
ZillyaTrojan.Generic.Win32.902749
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.62f640250a8e1d7d
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Ursu.332044
JiangminTrojan.Generic.difij
AviraTR/Dropper.MSIL.Gen
Antiy-AVLTrojan/Win32.Occamy
ArcabitTrojan.Ursu.D5110C
MicrosoftBackdoor:MSIL/Bladabindi!rfn
GoogleDetected
AhnLab-V3Trojan/Win32.Injector.C3029936
Acronissuspicious
BitDefenderThetaGen:NN.ZemsilF.34796.rm0@aSF@o4m
ALYacGen:Variant.Ursu.332044
MAXmalware (ai score=100)
VBA32TScope.Trojan.MSIL
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:T6dty7h+MTlYcprhYTAO2w)
YandexTrojan.Agent!47rBYMda68E
IkarusTrojan.MSIL.Krypt
MaxSecureTrojan.Malware.7164915.susgen
FortinetMSIL/GenKryptik.ESUKI!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.50a8e1
PandaTrj/CI.A

How to remove Ursu.332044?

Ursu.332044 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment