Malware

What is “Ursu.372426 (B)”?

Malware Removal

The Ursu.372426 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.372426 (B) virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Ursu.372426 (B)?


File Info:

name: 8B16663CFB99DB3167D7.mlw
path: /opt/CAPEv2/storage/binaries/f1d54be05c752d6aa87762ade56fc19b0c7d7b9f1e736fe8a96e63ead9a5bc65
crc32: EE0B75D0
md5: 8b16663cfb99db3167d7c3cfda9c8c7b
sha1: beeb89a4f131c8a7438c1ecc973200f517c3c336
sha256: f1d54be05c752d6aa87762ade56fc19b0c7d7b9f1e736fe8a96e63ead9a5bc65
sha512: 5649774a24e41330c85c627135f67b137986a4c228c328261c948ee88e51df61b4519d0844ce1d6c740eb903f358f3112eba9ac0860b0926769a0bbcdaefc601
ssdeep: 12288:Hke7nbCmzG8Jqfb4OKEM27Sdijsd8VkKeWAGRr6kgU5NmdvRMU5:7DQb4BEV7udMpudU5NmdJMU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11CE45EBC76D185E1FC0FA171CD5139B86B968F0396606D8B5F8E39C6BB6A0A55C30C8C
sha3_384: 79b5f1e662187dfdf5fee84f0a6e514387a720f2d61def42306964b63834d8859ed7247b769f2990a20ec7227bc5e837
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-12-08 18:11:14

Version Info:

CompanyName: Adobe Inc.
FileDescription: Adobe Installer
FileVersion: 5.3.1.470
InternalName: Adobe Installer
LegalCopyright: © 2020 Adobe. All rights reserved.
OriginalFilename: Adobe Installer
ProductName: Adobe Installer
ProductVersion: 5.3.1.470
Translation: 0x0409 0x04b0

Ursu.372426 (B) also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.372426
FireEyeGeneric.mg.8b16663cfb99db31
McAfeeArtemis!8B16663CFB99
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005811481 )
K7GWTrojan ( 005811481 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZemsilF.34084.Rm0@aG1v6leG
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.ACKH
TrendMicro-HouseCallTROJ_GEN.R002C0WL921
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.372426
AvastWin32:HacktoolX-gen [Trj]
Ad-AwareGen:Variant.Ursu.372426
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0WL921
McAfee-GW-EditionBehavesLike.Win32.Generic.bh
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Ursu.372426 (B)
IkarusTrojan.MSIL.Injector
AviraTR/Kryptik.vrbez
Antiy-AVLTrojan/MSIL.Kryptik
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ViRobotTrojan.Win32.Z.Ursu.719360
GDataGen:Variant.Ursu.372426
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.NK.C4827035
ALYacGen:Variant.Ursu.372426
MalwarebytesTrojan.Injector
APEXMalicious
TencentWin32.Trojan.Generic.Eadi
MAXmalware (ai score=84)
FortinetMSIL/Injector.VRI!tr
AVGWin32:HacktoolX-gen [Trj]
Cybereasonmalicious.cfb99d
PandaTrj/GdSda.A

How to remove Ursu.372426 (B)?

Ursu.372426 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment