Malware

Ursu.6866 (B) (file analysis)

Malware Removal

The Ursu.6866 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.6866 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ursu.6866 (B)?


File Info:

name: C4B40A3E4CAEDC321C0B.mlw
path: /opt/CAPEv2/storage/binaries/b022a85f93124b8af568c6a47b29e457e667b45dad99adbc77828acd524fb28e
crc32: BEF3212E
md5: c4b40a3e4caedc321c0b690e8ecbbeb5
sha1: 0a988af38bc677596ef60fc212abcef1d919191c
sha256: b022a85f93124b8af568c6a47b29e457e667b45dad99adbc77828acd524fb28e
sha512: 7d3acb999ffb31a12779104c4fce2cc2ab231a4adefdccae12eca6897efb1e16ff0603a2d65604b6f1a853cdb3d11d35a5a5fa32590ef210013ae2cdf4194730
ssdeep: 1536:VJga1matQjfnTKJ3J0ed9iT0e/nYE7IJeDfR2+3w3T3tT10XY70ZWi6O2rli:7wjfnTKJ3JQTx17R2+I3Zbo1l2rY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16FC308C6A5EC4EB2DD7257F005F1FEE404239D7711B1AA1B5087B2480DB3AD71B22ADA
sha3_384: 79e91425544986fe2c33b66e928f2b05db8e10c86c5e9e7ad77ce319c9f7805f6c5dfde1df388fd8b8a9322b2dcda884
ep_bytes: 68682d4000e8eeffffff000000000000
timestamp: 2013-08-24 04:45:40

Version Info:

ProductName: WinRAR
CompanyName: Alexander Roshal
FileDescription: WinRAR archiver
FileVersion: 4.20.0
ProductVersion: 4.20.0
InternalName: WinRAR
LegalCopyright: Copyright © Alexander Roshal 1993-2012
OriginalFilename: WinRAR.exe
Translation: 0x0409 0x04e4

Ursu.6866 (B) also known as:

MicroWorld-eScanGen:Variant.Ursu.6866
ClamAVWin.Dropper.DarkKomet-9872305-0
FireEyeGeneric.mg.c4b40a3e4caedc32
McAfeePWSZbot-FSD!C4B40A3E4CAE
CylanceUnsafe
VIPREGen:Variant.Ursu.6866
SangforVISUAL BASIC4
K7AntiVirusEmailWorm ( 004c16271 )
K7GWEmailWorm ( 004c16271 )
Cybereasonmalicious.e4caed
SymantecTrojan.Gen.MBT
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.BEAF
APEXMalicious
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.6866
NANO-AntivirusTrojan.Win32.Inject.ccjrgv
AvastWin32:Malware-gen
TencentWin32.Trojan.Dropper.Szbg
Ad-AwareGen:Variant.Ursu.6866
EmsisoftGen:Variant.Ursu.6866 (B)
ComodoMalware@#1cr11w8docbem
DrWebWin32.HLLW.VBNA
ZillyaTrojan.Injector.Win32.209522
McAfee-GW-EditionPWSZbot-FSD!C4B40A3E4CAE
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Ursu.6866
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.24D
ArcabitTrojan.Ursu.D1AD2
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
ALYacGen:Variant.Ursu.6866
MAXmalware (ai score=83)
VBA32Malware-Cryptor.VB.gen.1
RisingMalware.Undefined!8.C (TFE:3:DUne2dg3q1Q)
YandexTrojan.GenAsa!j6ShHgvRak4
IkarusWorm.Win32.Rebhip
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.DDOC!tr
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ursu.6866 (B)?

Ursu.6866 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment