Malware

What is “Ursu.45156”?

Malware Removal

The Ursu.45156 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.45156 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ursu.45156?


File Info:

name: 82FC9C441C1A8E910CDE.mlw
path: /opt/CAPEv2/storage/binaries/66eec635ea270249cceb7aa84ab3fca687e0c59388330068dd9df98e0b4dc26b
crc32: 813DE556
md5: 82fc9c441c1a8e910cdeb92ebe7ff2bc
sha1: 7e3ec274a43dfb1e92f54a811165449a18b4a723
sha256: 66eec635ea270249cceb7aa84ab3fca687e0c59388330068dd9df98e0b4dc26b
sha512: d99aad9e539ac62b6d118714423fda605c63719c2747b74f57951e9340d95cc754794419c5bd771667ed363d9da87c6b821e9b7bb8582e0b0763d1cac42e3b71
ssdeep: 24576:LWo1gmZBOmP9fe2+qMs0MZH6w+kwRx8iBaHRz7fj0YQWdoePlqlq7WwOEmP3/+RT:RtLOYkemkwTjBaHpL5Xn0lwoPv+aXE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15B75335E8DD042F9C9D60277426BFFF061F1BB3D5822463B9B928BBC97731462BA4250
sha3_384: d697618df67d81529ab44ce77a6de2aaebf6ba41a390c24d1c3931a4bebf9fcb8b2d32150b75078ee7684c58869220fe
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2014-03-22 07:23:01

Version Info:

CompanyName: 快屏网络科技有限公司
FileDescription: 小熊日历安装程序
FileVersion: V1.0
InternalName: $Name
LegalCopyright: Copyright (C) 2014快屏网络
LegalTrademarks: 快屏网络
ProductName: 小熊日历
ProductVersion: 1.0.0.0
Translation: 0x0804 0x03a8

Ursu.45156 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Ursu.45156
FireEyeGeneric.mg.82fc9c441c1a8e91
CAT-QuickHealTrojan.MauvaiseRI.S5245166
SkyhighArtemis!Trojan
McAfeeArtemis!82FC9C441C1A
MalwarebytesPUP.Optional.ChinAd.DDS
VIPREGen:Variant.Ursu.45156
SangforTrojan.Win32.Save.a
Cybereasonmalicious.41c1a8
VirITTrojan.Win32.KillFiles.BQFE
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.NSISmod.A suspicious
AvastWin32:Evo-gen [Trj]
KasperskyTrojan.Win32.Pincav.cxpm
BitDefenderGen:Variant.Ursu.45156
NANO-AntivirusTrojan.Win32.Pincav.dtlemb
TencentBackdoor.Win32.Poison.pb
SophosGeneric ML PUA (PUA)
DrWebTrojan.KillFiles.28526
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Ursu.45156 (B)
MAXmalware (ai score=82)
GoogleDetected
VaristW32/Xpyn.A.gen!Eldorado
Antiy-AVLGrayWare[AdWare]/Win32.PackedNsisMod.a
MicrosoftProgram:Win32/Wacapew.C!ml
ArcabitTrojan.Ursu.DB064
ZoneAlarmTrojan.Win32.Pincav.cxpm
GDataGen:Variant.Ursu.45156
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.45156
VBA32Malware-Cryptor.Inject.gen
Cylanceunsafe
RisingMalware.NSISMod!1.DBC4 (CLASSIC)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Pincav.CXPM!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_70% (W)

How to remove Ursu.45156?

Ursu.45156 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment