Malware

Ursu.45882 removal instruction

Malware Removal

The Ursu.45882 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.45882 virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ursu.45882?


File Info:

name: 00A3E593AF2DAB8AA78D.mlw
path: /opt/CAPEv2/storage/binaries/f481db654987c7c4ff51d2ec5d33e2407dd13746d734be4298f5cda27a474a8e
crc32: 26476CBB
md5: 00a3e593af2dab8aa78d31b31ea84077
sha1: 10e61f87ecb47dc00f946da18ae8caa4c1a8803b
sha256: f481db654987c7c4ff51d2ec5d33e2407dd13746d734be4298f5cda27a474a8e
sha512: 29b7e398a0992e114667ba65dc2949037fc4beeb2280b56c5d11d440eb4092beaf0c923e50d3085711dc708c62855332f1d2c1e559b7532ee9a0c5e7a78a7703
ssdeep: 3072:ercDFxUcrRmqz0HJ+DYP9pLcvQULhf7rIcmlduMXhOgim:eruz0kYlpL1UNfIhldTF
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T162B3E14F7EE0D9F3F4520A700E7B5FABB3B6E221013547A35B609A09B5731978D26392
sha3_384: bc3e139ed436c996882f0f6c1dc1bc37474a3e6757b266fe5d2049cdc7ac00906241103a277cc18d00d9cf3c4c70c378
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2014-03-22 07:23:01

Version Info:

CompanyName: 快屏网络科技有限公司
FileDescription: 天马日历安装程序
FileVersion: V1.0
InternalName: $Name
LegalCopyright: Copyright (C) 2014快屏网络
LegalTrademarks: 快屏网络
ProductName: 天马日历
ProductVersion: 1.0.0.0
Translation: 0x0804 0x03a8

Ursu.45882 also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Ursu.45882
FireEyeGeneric.mg.00a3e593af2dab8a
CAT-QuickHealTrojan.MauvaiseRI.S5245166
SkyhighBehavesLike.Win32.Trojan.cc
ALYacGen:Variant.Ursu.45882
ZillyaAdware.GenericKD.Win32.5894
SangforTrojan.Win32.Save.a
VirITTrojan.Win32.KillFiles.BQFE
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.NSISmod.A suspicious
ClamAVWin.Trojan.15173305-1
Kasperskynot-a-virus:HEUR:AdWare.NSIS.Xpyn.heur
BitDefenderGen:Variant.Ursu.45882
NANO-AntivirusTrojan.Win32.Pincav.dtlemb
AvastWin32:Malware-gen
TencentBackdoor.Win32.Poison.pb
EmsisoftGen:Variant.Ursu.45882 (B)
DrWebTrojan.KillFiles.28526
VIPREGen:Variant.Ursu.45882
Trapminemalicious.moderate.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Ursu.45882
GoogleDetected
VaristW32/Xpyn.A.gen!Eldorado
Antiy-AVLGrayWare[AdWare]/Win32.PackedNsisMod.a
Kingsoftmalware.kb.a.885
ArcabitTrojan.Ursu.DB33A
ZoneAlarmnot-a-virus:HEUR:AdWare.NSIS.Xpyn.heur
MicrosoftProgram:Win32/Wacapew.C!ml
CynetMalicious (score: 100)
MAXmalware (ai score=81)
VBA32Adware.NSIS.Xpyn
MalwarebytesPUP.Optional.ChinAd.DDS
RisingMalware.NSISMod!1.DBC4 (CLASSIC)
YandexTrojan.GenAsa!hrZneoTQ9ng
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_90% (D)

How to remove Ursu.45882?

Ursu.45882 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment