Malware

What is “Ursu.439982”?

Malware Removal

The Ursu.439982 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.439982 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Anomalous binary characteristics

How to determine Ursu.439982?


File Info:

name: F49AD1EC9801F4157B9C.mlw
path: /opt/CAPEv2/storage/binaries/9c2cd69fce2993901198dfdb668d4d7ee90a81326929bd45553d817472095f15
crc32: 7C807B0D
md5: f49ad1ec9801f4157b9cd14a3433c3ab
sha1: c3bc8045b38b6f96b0fb711e2acf89c14be20764
sha256: 9c2cd69fce2993901198dfdb668d4d7ee90a81326929bd45553d817472095f15
sha512: 9f958d3fcd7f66c23fb6352fbb767a98c91972537468b36b77a89229aeec92f67796df59bc31134e4ef0e4eb5faccd7cf32f2ca2248e8fbb184b1e9c13e77ca5
ssdeep: 768:0ic/FJux5G8n+X2o9S/LVTMb2DKZXFG+Q:s/25Gfx9U5wjUV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B9C2D00717C34C37C9BC4F7107632AA0A392D65929EA4A37C6D59A7DAFB61510FB2343
sha3_384: 0b5c82842895f29e2137b61eef13407a3bd8edb184fd05b49cc2a81e036931f08949bf3db4d850c2871680fada45ea80
ep_bytes: ff250020400000000000000000000000
timestamp: 2009-04-05 09:38:32

Version Info:

0: [No Data]

Ursu.439982 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner.25074
MicroWorld-eScanGen:Variant.Ursu.439982
FireEyeGeneric.mg.f49ad1ec9801f415
ALYacGen:Variant.Ursu.439982
CylanceUnsafe
ZillyaTrojan.Generic.Win32.349169
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Jorik.1011a4e1
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.c9801f
BitDefenderThetaGen:NN.ZemsilF.34084.bmY@aSFtSnl
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-1163927
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.439982
NANO-AntivirusTrojan.Win32.Autoruner.fknpqa
SUPERAntiSpywareTrojan.Agent/Gen-Gal
AvastMSIL:Bladabindi-HZ [Wrm]
TencentWin32.Trojan.Generic.Eddq
Ad-AwareGen:Variant.Ursu.439982
EmsisoftGen:Variant.Ursu.439982 (B)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.mc
SophosMal/Generic-S
GDataGen:Variant.Ursu.439982
AviraHEUR/AGEN.1121954
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.1A17A9
MicrosoftBackdoor:Win32/Bladabindi!ml
CynetMalicious (score: 100)
McAfeeRDN/Generic.grp
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Agent.MSIL
YandexTrojan.Agent!wCWf5MZXdE0
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Generic.DN.112C3C!tr
AVGMSIL:Bladabindi-HZ [Wrm]
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Ursu.439982?

Ursu.439982 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment