Malware

What is “Ursu.724975”?

Malware Removal

The Ursu.724975 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.724975 virus can do?

  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ursu.724975?


File Info:

name: 01A56B91E6BE8600D279.mlw
path: /opt/CAPEv2/storage/binaries/1f954911064d71b0458b016f2b4e6a3998b4be93101322a2d83f8336990fc4de
crc32: C2EC896A
md5: 01a56b91e6be8600d279a053e542681a
sha1: a8b1c28d3f6d977f9d2abf386197c57de67667a6
sha256: 1f954911064d71b0458b016f2b4e6a3998b4be93101322a2d83f8336990fc4de
sha512: f84c74cbfd93a0b80bbcdb881b80205529a7437c932b898ff9e438004910d919d5662d33e38687ee9215205ac7c4a5fd4f561af59b101e459f280b0c2c12e432
ssdeep: 12288:gP9+zE1Vn8y6eB/JzN44YkXsvwkZ3zCq6SX9kuLT2tN1w1f9V58Ve3CGKhIkmdq:gP9D1V/rzN44DGlz6S3MI978Vl6q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13F45CFCAD16E44D2DC053FF598242AC75B2447328BB400283A6FBD495F7B5FAC05EEA6
sha3_384: 0911b8f53a2ee606424cdc570d571742ad5deaa87029ba53faf905ea79c7a94a2c8dd8c462ddee262bf0950a07b3372b
ep_bytes: 68a4184000e8f0ffffff000000000000
timestamp: 2015-03-24 12:04:40

Version Info:

Translation: 0x0409 0x04b0
CompanyName: OFFICE
ProductName: AdobeUpdate
FileVersion: 11.00.0009
ProductVersion: 11.00.0009
InternalName: AdobeUpdate
OriginalFilename: AdobeUpdate.exe

Ursu.724975 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Multi.Generic.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Ursu.724975
FireEyeGeneric.mg.01a56b91e6be8600
McAfeeArtemis!01A56B91E6BE
CylanceUnsafe
ZillyaTrojan.Agent.Win32.585922
Sangfor[MICROSOFT VISUAL BASIC 5.0]
K7AntiVirusSpyware ( 004d53c91 )
AlibabaTrojanSpy:Win32/Generic.b90349aa
K7GWSpyware ( 004d53c91 )
Cybereasonmalicious.1e6be8
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Agent.OTJ
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderGen:Variant.Ursu.724975
NANO-AntivirusTrojan.Win32.Agent.ebjjba
AvastWin32:Malware-gen
TencentWin32.Trojan.Spy.Een
Ad-AwareGen:Variant.Ursu.724975
EmsisoftGen:Variant.Ursu.724975 (B)
VIPREGen:Variant.Ursu.724975
McAfee-GW-EditionBehavesLike.Win32.Trojan.tt
Trapminemalicious.moderate.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
AviraTR/Spy.Agent.1232896.79
MicrosoftTrojanSpy:Win32/Skeeyah.A!rfn
ArcabitTrojan.Ursu.DB0FEF
GDataGen:Variant.Ursu.724975
GoogleDetected
ALYacGen:Variant.Ursu.724975
MAXmalware (ai score=99)
RisingSpyware.Agent!8.C6 (TFE:5:UVHZH8idiAU)
YandexTrojan.GenAsa!v/DqJYxylcs
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Malware.74757689.susgen
FortinetW32/VBKrypt.C!tr
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ursu.724975?

Ursu.724975 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment