Malware

About “Ursu.702” infection

Malware Removal

The Ursu.702 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.702 virus can do?

  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ursu.702?


File Info:

crc32: B4A75198
md5: 9b7d885d07d800222ae72cd4e5a0a56a
name: 9B7D885D07D800222AE72CD4E5A0A56A.mlw
sha1: b2c965748d396ff88fb83a7abcd00e0cc6948640
sha256: dcbcae3ca9905526043a44114ca4bbdcb60da2e037ec213728932ad1c1bf8c5c
sha512: db68b7220a7adc871ef21da58c1dcd9105483bbb0f876da261d303477554d6ec0cbc1a5728f724fe5f705ded8c3e388db05e30683c2779527b9df7b29c813faa
ssdeep: 48:6GQLUmruXUfQ3qAGeLWDJtUSL83qx3DgXulPlFRFWSfbNtm:4jruXp6AGeLAUSLOqZVdlFjzNt
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: tlc.exe
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
FileDescription:
OriginalFilename: tlc.exe

Ursu.702 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.702
FireEyeGeneric.mg.9b7d885d07d80022
ALYacGen:Variant.Ursu.702
CylanceUnsafe
SangforMalware
K7AntiVirusTrojan ( 004f9af71 )
BitDefenderGen:Variant.Ursu.702
K7GWTrojan ( 004f9af71 )
CrowdStrikewin/malicious_confidence_70% (D)
CyrenW32/S-f5d6a516!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Rootkit-gen [Rtk]
KasperskyUDS:DangerousObject.Multi.Generic
NANO-AntivirusTrojan.Win32.Zusy.enrkiq
RisingTrojan.Injector!8.C4 (TFE:C:2nOdauBXyMQ)
Ad-AwareGen:Variant.Ursu.702
EmsisoftGen:Variant.Ursu.702 (B)
ComodoTrojWare.MSIL.Zusy.WS@6l6lgw
F-SecureHeuristic.HEUR/AGEN.1122400
DrWebTrojan.Starter.7894
ZillyaTrojan.Injector.Win32.411770
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-R + Troj/Kryptik-HS
IkarusTrojan.MSIL.Injector
AviraHEUR/AGEN.1122400
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftTrojan:Win32/Dynamer!ac
ArcabitTrojan.Ursu.702
SUPERAntiSpywareTrojan.Agent/Gen-Injector
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Ursu.702
CynetMalicious (score: 90)
AhnLab-V3Trojan/Win32.Injector.R288829
McAfeeArtemis!9B7D885D07D8
MalwarebytesTrojan.Agent.MSIL
ESET-NOD32a variant of MSIL/Injector.QJL
TencentWin32.Trojan.Ursu.Hvjh
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_80%
FortinetMSIL/Injector.QJL!tr
BitDefenderThetaGen:NN.ZemsilF.34804.am0@aamvSxc
AVGWin32:Rootkit-gen [Rtk]
Cybereasonmalicious.d07d80
Paloaltogeneric.ml
Qihoo-360Win32/RootKit.Rootkit.7e5

How to remove Ursu.702?

Ursu.702 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment