Malware

Should I remove “Ursu.376120”?

Malware Removal

The Ursu.376120 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.376120 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Ursu.376120?


File Info:

name: 8E540F038D41ED0B7EBF.mlw
path: /opt/CAPEv2/storage/binaries/f8bbcceca00276591c05495f600a4310cb22265621dd1b87d6adf412d07a7f18
crc32: D29F99A3
md5: 8e540f038d41ed0b7ebf2231f03d694e
sha1: 2a59e8911e8e3d14c64d713acbd861f3ca5c354a
sha256: f8bbcceca00276591c05495f600a4310cb22265621dd1b87d6adf412d07a7f18
sha512: 264430d11f24f81fb11fe7c53239ea7d459f25e6bfac2912af73f7d6000d7a4d682ad0852155b4a2e3c3eaa9e74db66b10d2a32fe0ed5488d4ecde77230289bb
ssdeep: 192:q4L9SvCTVSnlYJLLLTDKnHssSDrKUgTWGU10:q4LACT1PLTD+eDrQTWGN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19D22E95967C48363D77B077688B3164103B6AD14AA67AFAF1450BFF7BC832490622A36
sha3_384: 677b0af390346544fb85f9e89afd6eae9460591b2ed02184fd07e15d3ecd5692fed86c5996608e418bd63b9951d61f1d
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-12-04 18:36:24

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: VLC media player.exe
LegalCopyright:
OriginalFilename: VLC media player.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Ursu.376120 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.376120
FireEyeGeneric.mg.8e540f038d41ed0b
ALYacGen:Variant.Ursu.376120
CylanceUnsafe
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.38d41e
BitDefenderThetaGen:NN.ZemsilF.34062.am0@aGNSLxo
CyrenW32/Razy.CL.gen!Eldorado
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.MSIL.Hesv.gen
BitDefenderGen:Variant.Ursu.376120
AvastFileRepMalware
Ad-AwareGen:Variant.Ursu.376120
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Ursu.376120 (B)
APEXMalicious
GDataGen:Variant.Ursu.376120
eGambitUnsafe.AI_Score_99%
AviraHEUR/AGEN.1203855
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
McAfeeGenericRXGT-XU!8E540F038D41
MAXmalware (ai score=85)
IkarusTrojan.Hesv
FortinetMSIL/Hesv.XU!tr
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Ursu.376120?

Ursu.376120 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment