Malware

How to remove “Ursu.45882”?

Malware Removal

The Ursu.45882 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.45882 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ursu.45882?


File Info:

name: A3ABA8EF9B60B0DE9242.mlw
path: /opt/CAPEv2/storage/binaries/b057c2b8b5bf216ecdfa8d658b18daae3b682318efebcc11f1b2eb30531f4f9e
crc32: B9C2FBA3
md5: a3aba8ef9b60b0de92426c7d5c3ff5f2
sha1: 6836cef789eb41eaad696c65a75db8c8b6d249e7
sha256: b057c2b8b5bf216ecdfa8d658b18daae3b682318efebcc11f1b2eb30531f4f9e
sha512: 53a5290613fac73fedbb68997c213df0e79b739e049a3cac23de2fdff1ebf01834ad2c3b6f114d5036428c213e9767f8910f8b40c2f6bdbe2a4ca2ac2769a156
ssdeep: 3072:zrcDFxUcrRmqz0HJ+DuPwWNyfsY9S0FbMUEkSjdSIJfYUjr6TQ/+LSVL0rl:zruz0kuoWNyf9S0NQMKD+2Vul
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13DE3F21A79D4D8FBE5580F70067A6B63F3F5E328016297076B248A4C7E23AD61D1C3A3
sha3_384: 7ad7766221d80724fb765be46e7b0e32d0ae82dbb8e4ffcb2ab3f366eec285a9682a5ec303dbbadb33bd9477e506bc30
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2014-03-22 07:23:01

Version Info:

CompanyName: 快屏网络科技有限公司
FileDescription: 天马日历安装程序
FileVersion: V1.0
InternalName: $Name
LegalCopyright: Copyright (C) 2014快屏网络
LegalTrademarks: 快屏网络
ProductName: 天马日历
ProductVersion: 1.0.0.0
Translation: 0x0804 0x03a8

Ursu.45882 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.45882
FireEyeGeneric.mg.a3aba8ef9b60b0de
CAT-QuickHealTrojan.MauvaiseRI.S5245166
SkyhighBehavesLike.Win32.Trojan.cc
ZillyaAdware.Xpyn.Win32.229
SangforTrojan.Win32.Save.a
CrowdStrikewin/grayware_confidence_70% (D)
ArcabitTrojan.Ursu.DB33A
VirITTrojan.Win32.KillFiles.BQFE
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.NSISmod.A suspicious
CynetMalicious (score: 100)
ClamAVWin.Trojan.15173305-1
Kasperskynot-a-virus:HEUR:AdWare.NSIS.Xpyn.heur
BitDefenderGen:Variant.Ursu.45882
NANO-AntivirusTrojan.Win32.Pincav.dtlemb
AvastWin32:Malware-gen
TencentBackdoor.Win32.Poison.pb
EmsisoftGen:Variant.Ursu.45882 (B)
DrWebTrojan.KillFiles.28526
VIPREGen:Variant.Ursu.45882
Trapminemalicious.moderate.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
VaristW32/Xpyn.A.gen!Eldorado
Antiy-AVLGrayWare[AdWare]/Win32.PackedNsisMod.a
Kingsoftmalware.kb.a.757
MicrosoftProgram:Win32/Wacapew.C!ml
ZoneAlarmnot-a-virus:HEUR:AdWare.NSIS.Xpyn.heur
GDataGen:Variant.Ursu.45882
GoogleDetected
ALYacGen:Variant.Ursu.45882
MAXmalware (ai score=81)
VBA32Adware.NSIS.Xpyn
MalwarebytesPUP.Optional.ChinAd.DDS
RisingMalware.NSISMod!1.DBC4 (CLASSIC)
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Ursu.45882?

Ursu.45882 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment