Malware

Ursu.721756 removal instruction

Malware Removal

The Ursu.721756 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.721756 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • CAPE detected the embedded win api malware family
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Ursu.721756?


File Info:

name: 092A7D7B68E1566638EF.mlw
path: /opt/CAPEv2/storage/binaries/1c4622bf31688ece82308c1939f1a27ae5dc905ab1ea3e7d1fcc84e9723d0b7b
crc32: 21C80DE3
md5: 092a7d7b68e1566638efa7b5356a8ca4
sha1: 01803f02f7a24c6119b0c259ce54881cd2845eb2
sha256: 1c4622bf31688ece82308c1939f1a27ae5dc905ab1ea3e7d1fcc84e9723d0b7b
sha512: 6763bf9992a62ad61e9bac3b797751c47737110221ee86c6fa94b56d4f5fd8ad8a894b14f7c139322710fa2bbaf2efb59d27edcb5bf94f9018c98dd7ef1b3974
ssdeep: 98304:O06FOznLo0+Dd6uxcJhkjthplRbTuPn47Rd+yjmoU2DrQbc:O3F6n80W6uGJ8t/HbqQ7RdrtDr4c
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FC262352F7D2D0B0D8BA05B2052586B54F793D7297BAC5F76F802EAECC303D0AA35646
sha3_384: bacedb4010e3d6dbd18957f15d40ac730ba11b8a77601542309e4d54dfdd7a8b019b79b5bda6c337a54ed80121b5f523
ep_bytes: e8a61d0000e989feffff8bff565733f6
timestamp: 2012-06-14 16:16:10

Version Info:

Comments: Created with Setup Factory
FileDescription: Setup Application
FileVersion: 9.1.0.0
InternalName: suf_launch
LegalCopyright: Setup Engine Copyright © 2004-2012 Indigo Rose Corporation
LegalTrademarks: Setup Factory is a trademark of Indigo Rose Corporation.
OriginalFilename: suf_launch.exe
ProductName: Setup Factory Runtime
ProductVersion: 9.1.0.0
Translation: 0x0409 0x04e4

Ursu.721756 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Ursu.721756
FireEyeGen:Variant.Ursu.721756
SkyhighBehavesLike.Win32.BadFile.rc
McAfeeArtemis!092A7D7B68E1
MalwarebytesGeneric.Malware/Suspicious
VIPREGen:Variant.Ursu.721756
SangforTrojan.Win32.Ursu.Vm3o
Elasticmalicious (high confidence)
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Ursu.721756
AvastWin32:Malware-gen
EmsisoftGen:Variant.Ursu.721756 (B)
GDataGen:Variant.Ursu.721756
XcitiumMalware@#38nn4kolijxpf
ArcabitTrojan.Ursu.DB035C
BitDefenderThetaGen:NN.ZedlaF.36744.vz8aaqlCRooO
ALYacGen:Variant.Ursu.721756
MAXmalware (ai score=80)
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H09IE23
MaxSecureTrojan.Malware.218946355.susgen
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Ursu.721756?

Ursu.721756 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment