Malware

Should I remove “Ursu.5651”?

Malware Removal

The Ursu.5651 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.5651 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the PyInstaller malware family

How to determine Ursu.5651?


File Info:

name: 51CE2F5EEFD6283560EB.mlw
path: /opt/CAPEv2/storage/binaries/a060b65b29cc1c387232fd10754058c9ac329c3138a575377dd8326eac5b6b04
crc32: 072B8624
md5: 51ce2f5eefd6283560eb170a859e7152
sha1: f1e730b895cda60aa786c1fb24a4bec1298053c5
sha256: a060b65b29cc1c387232fd10754058c9ac329c3138a575377dd8326eac5b6b04
sha512: 3d23479dec9b8cca5b32fcf3aa201c46ae054f347c154433b40ebd150dda81da0c66a5f5aeec6842a7067038f4222c3583fef85be04a20e218154071ccbfa49b
ssdeep: 196608:VngesUJgcg9ZNpUNW0vOLSHDLRNGLTIS2pOYILgqlRnM0XF4Xf:xgtUJNg9TCEwh60S4O/86yXf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C196CF213B904566C56F03337FA9E124E0A96D14163D8DC713847A1B2D7FBD27A2AEF2
sha3_384: d647ef75393224b6e7a1bf258ad77e52b248ca691633fe970149897bf26581e99a872b560b982520a69d49fc673e6630
ep_bytes: ff250020400000000000000000000000
timestamp: 2019-01-05 02:31:20

Version Info:

Translation: 0x0000 0x04b0
Comments: TurboTax 2018 Installer
FileDescription: Application
FileVersion: 5.6.2.9
InternalName: setup.exe
LegalCopyright: TurboTax 2018
OriginalFilename: setup.exe
ProductName: TurboTax 2018 Installer
ProductVersion: 5.6.2.9
Assembly Version: 37.8.9.0

Ursu.5651 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.DownLoader15.29994
MicroWorld-eScanGen:Variant.Ursu.5651
FireEyeGeneric.mg.51ce2f5eefd62835
McAfeeArtemis!51CE2F5EEFD6
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1087912
K7AntiVirusTrojan ( 700000121 )
AlibabaTrojan:MSIL/CoinMiner.936b83e2
K7GWTrojan ( 700000121 )
Cybereasonmalicious.eefd62
BitDefenderThetaGen:NN.ZemsilF.34182.@t0@auGH3zp
VirITTrojan.Win32.Dnldr15.BSJQ
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.BVF
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyTrojan.Win32.Agent.qwhvzx
BitDefenderGen:Variant.Ursu.5651
NANO-AntivirusTrojan.Win32.Dwn.ewsrmc
AvastWin32:RATX-gen [Trj]
TencentWin32.Trojan.Agent.Svrq
EmsisoftGen:Variant.Ursu.5651 (B)
ComodoMalware@#8k4ls9pirlhw
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
JiangminTrojan.Agent.cupd
MaxSecureTrojan.Malware.11913.susgen
AviraHEUR/AGEN.1141855
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.2A21C35
MicrosoftTrojan:Win32/Tnega!ml
ZoneAlarmTrojan.Win32.Agent.qwhvzx
GDataGen:Variant.Ursu.5651
AhnLab-V3Trojan/Win32.RL_Generic.C3985017
ALYacGen:Variant.Ursu.5651
APEXMalicious
RisingTrojan.Generic/MSIL@AI.98 (RDM.MSIL:v0+PJudSRf/OMZM9RmE/ig)
YandexTrojan.Agent!ybOgmNgDY2Q
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Agent.BVF!tr
WebrootW32.Trojan.Gen
AVGWin32:RATX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Ursu.5651?

Ursu.5651 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment