Malware

Ursu.378361 removal guide

Malware Removal

The Ursu.378361 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.378361 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ursu.378361?


File Info:

name: 1D62AE1AD9DE43D81FA3.mlw
path: /opt/CAPEv2/storage/binaries/5fd85d0c0c5cc0b36372522617bb4bae4d4d365c5b741d664f55d315b9d284f5
crc32: 1DD0A6FA
md5: 1d62ae1ad9de43d81fa3fb2ac50c8494
sha1: 8def7246c885744780070d6bdcc062cb699f42a0
sha256: 5fd85d0c0c5cc0b36372522617bb4bae4d4d365c5b741d664f55d315b9d284f5
sha512: 9e3c34d640b700afacfca0084e5fd61e1f3a2c1c63c2bb6b53a23d34c38c632bbf73cea3d3cc61b56ba2c9fc676364b291f6ddb0e7435bda2314e4c32d823b59
ssdeep: 12288:wTtiQJ+O4/AEW51HOwq/bYBwNvL4VkHwfmYXwx9L+fN:8IQcNL6JjqYBwNDk+4w9L2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T144A41253BBE1CEF4D1E11232C9825FA425B8EEA5171119C3A3845E0D5FB16E1AB3B18F
sha3_384: 27d04471d8cb75ac5e8f7788fa13faafca4ccce20e503f7bb538579cd641eeaf32e622d75f6354d431f607da5e5cb3cb
ep_bytes: 558bec6aff68408e410068505e410064
timestamp: 2011-04-28 11:38:36

Version Info:

CompanyName: Sergei Strelec
FileDescription: ProgramPE
FileVersion: 1.4.1.2100
InternalName: 7ZSfxMod
LegalCopyright: Copyright © 2005-2010 Oleg N. Scherbakov
OriginalFilename: 7ZSfxMod_x86.exe
PrivateBuild: April 28, 2011
ProductName: 7-Zip SFX
ProductVersion: 1.4.1.2100
Translation: 0x0000 0x04b0

Ursu.378361 also known as:

ClamAVWin.Trojan.Generic-9784821-0
ALYacGen:Variant.Ursu.378361
VIPRETrojan.Win32.Generic!BT
BitDefenderGen:Variant.Ursu.378361
Cybereasonmalicious.ad9de4
MicroWorld-eScanGen:Variant.Ursu.378361
RisingTrojan.Zpevdo!8.F912 (CLOUD)
EmsisoftGen:Variant.Ursu.378361 (B)
ComodoBackdoor.Win32.Androm.XTA@4z809t
TrendMicroTROJ_GEN.R002C0PDP21
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGen:Variant.Ursu.378361
SophosGeneric PUA IH (PUA)
JiangminBackdoor.Azbreg.ah
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Ursu.378361
TrendMicro-HouseCallTROJ_GEN.R002C0PDP21
FortinetW32/GenericRXHA.IH!tr

How to remove Ursu.378361?

Ursu.378361 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment