Malware

What is “Ursu.45882”?

Malware Removal

The Ursu.45882 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.45882 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ursu.45882?


File Info:

name: 784F210755ADF1BE487D.mlw
path: /opt/CAPEv2/storage/binaries/cd8b52db7c05debda153df617c0cd94b5763123f19403d8086d3246b90a55164
crc32: 1DDF8770
md5: 784f210755adf1be487d3ed36aada509
sha1: 3b0ff586f0d6d60101fa15db5c068a062d7fb0b1
sha256: cd8b52db7c05debda153df617c0cd94b5763123f19403d8086d3246b90a55164
sha512: 1e8cebf891bdd8271da087b1eb00dcb5fa1468a16ff33ecefdf142759442d9260f609fffb71ba2113ea8a251ede088808b04e3e3ccf08bb90b9f39baa1c44fe9
ssdeep: 49152:3/hmg0fmAvoNUNs6XXPLqk2Ew7hu91TSusxZBMxW53j/y:3/hmgxKNsUq5tlu9INBMxW53W
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1247533EAFBB469B7E69502FA0B720790E2FF9CD3A520071F1B61C74575882C48D489F6
sha3_384: d408b22514d358cdcc2f2ad8a39a818dde19b6749fa88e90b911f97e1eded3bf0222caf0f8635be57744efd0053a5001
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2014-03-22 07:23:01

Version Info:

CompanyName: 快屏网络科技有限公司
FileDescription: 天马日历安装程序
FileVersion: V1.0
InternalName: $Name
LegalCopyright: Copyright (C) 2014快屏网络
LegalTrademarks: 快屏网络
ProductName: 天马日历
ProductVersion: 1.0.0.0
Translation: 0x0804 0x03a8

Ursu.45882 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Ursu.45882
ClamAVWin.Trojan.15173305-1
FireEyeGeneric.mg.784f210755adf1be
CAT-QuickHealTrojan.MauvaiseRI.S5245166
ALYacGen:Variant.Ursu.45882
VIPREGen:Variant.Ursu.45882
SangforTrojan.Win32.Save.a
VirITTrojan.Win32.KillFiles.BQFE
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.NSISmod.A suspicious
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:AdWare.NSIS.Xpyn.heur
BitDefenderGen:Variant.Ursu.45882
NANO-AntivirusTrojan.Win32.Pincav.dtlemb
TencentBackdoor.Win32.Poison.pb
SophosGeneric ML PUA (PUA)
DrWebTrojan.KillFiles.28526
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Ursu.45882 (B)
GDataGen:Variant.Ursu.45882
GoogleDetected
Antiy-AVLGrayWare[AdWare]/Win32.PackedNsisMod.a
ArcabitTrojan.Ursu.DB33A
ZoneAlarmnot-a-virus:HEUR:AdWare.NSIS.Xpyn.heur
MicrosoftProgram:Win32/Wacapew.C!ml
VaristW32/Xpyn.A.gen!Eldorado
MAXmalware (ai score=83)
VBA32Adware.NSIS.Xpyn
MalwarebytesPUP.Optional.ChinAd.DDS
RisingMalware.NSISMod!1.DBC4 (CLASSIC)
YandexTrojan.GenAsa!hrZneoTQ9ng
SentinelOneStatic AI – Malicious PE
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_60% (D)

How to remove Ursu.45882?

Ursu.45882 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment