Malware

Ursu.351624 (file analysis)

Malware Removal

The Ursu.351624 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.351624 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Collects information about installed applications
  • Anomalous binary characteristics

How to determine Ursu.351624?


File Info:

name: 77C85F62FED5F8A03DA3.mlw
path: /opt/CAPEv2/storage/binaries/3afe00c1dd1e982eacb776cb2a472745f6461380f7ef7ac5f6e360ac9a29b3cb
crc32: 70C6EF06
md5: 77c85f62fed5f8a03da3190fddb6bd02
sha1: 5047fb5db7f2bb5a5897dce241caf47435ac1a2a
sha256: 3afe00c1dd1e982eacb776cb2a472745f6461380f7ef7ac5f6e360ac9a29b3cb
sha512: 02371a300dbb5b3c600b98cb7ab43bad97cb200220ff7a8e094af7d90a52c2eae2a9cdb07c777b536f61c9aca28b937d688714ce316b3367b3ad0d5cdeb9c446
ssdeep: 49152:8qaKzOywNAsLr/efh2vYh5OcO+2bHkHIp1ZJhgM68VXrRUEKCJzRLllshnDk/rRC:8bKzO/LrzvYh6kHunJ+M6YXrRU6JlLI9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BF761252C61D1B99FD6407FB081D6AB508C86DF13F3284F2ADD6340B46F89ED52A3A27
sha3_384: 933e0aebc1760d3575c88d72ec22770c07785018e828eaf492938fb69c8d1dc9831cc0b93f4be00000627ac32a7c881d
ep_bytes: e83a720000e9000000006a146858da45
timestamp: 2016-08-29 18:27:33

Version Info:

0: [No Data]

Ursu.351624 also known as:

BkavW32.AIDetect.malware1
LionicAdware.Win32.DownloadHelper.2!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.351624
FireEyeGeneric.mg.77c85f62fed5f8a0
McAfeeIStartSurf
CylanceUnsafe
ZillyaAdware.DownloadHelper.Win32.8291
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaAdWare:Win32/StartSurf.a8e34218
K7GWTrojan ( 00545d801 )
K7AntiVirusTrojan ( 00545d801 )
BitDefenderThetaGen:NN.ZexaF.34182.@RZ@aGbRf8oO
CyrenW32/Trojan.FLD.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HMFY
TrendMicro-HouseCallTrojanSpy.Win32.URSNIF.SMY.hp
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:AdWare.Win32.DownloadHelper.gen
BitDefenderGen:Variant.Ursu.351624
NANO-AntivirusRiskware.Win32.DownloadHelper.ftjeqv
AvastWin32:StartSurf-I [Adw]
TencentWin32.Trojan.Fakedoc.Auto
EmsisoftGen:Variant.Ursu.351624 (B)
ComodoApplication.Win32.AdLoad.BF@808b6c
TrendMicroTrojanSpy.Win32.URSNIF.SMY.hp
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.wm
SophosIStartSurfInstaller (PUA)
IkarusTrojan.Dropper
JiangminAdWare.DownloadHelper.etv
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2A3F650
MicrosoftTrojan:AndroidOS/Mploit!rfn
GDataGen:Variant.Ursu.351624
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.351624
MAXmalware (ai score=99)
MalwarebytesAdware.IStartSurf
APEXMalicious
RisingTrojan.Kryptik!1.B4F7 (CLOUD)
YandexPUA.DownloadHelper!md4hCB1pK+I
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GNDF!tr
AVGWin32:StartSurf-I [Adw]
Cybereasonmalicious.2fed5f
PandaTrj/GdSda.A

How to remove Ursu.351624?

Ursu.351624 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment