Malware

Should I remove “Ursu.732507”?

Malware Removal

The Ursu.732507 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.732507 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • CAPE detected the VMProtectStub malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Ursu.732507?


File Info:

name: F584A361E6E3DFDD4898.mlw
path: /opt/CAPEv2/storage/binaries/2ca5d9c0e2e82094947f5119fbf2d0da9c29e3fa9d3cff67596fe4aff035fee5
crc32: EC241457
md5: f584a361e6e3dfdd4898408996b3a88b
sha1: 954cff4fd038722e1fe599ba986551192742570f
sha256: 2ca5d9c0e2e82094947f5119fbf2d0da9c29e3fa9d3cff67596fe4aff035fee5
sha512: bb35b19fd68886350635955eb4cf2cb9aa90a6d7829dc6a903d333ad1e2ae2c11e503167666d16f927329a75c7585a92a3f1a97de490f6267ec27a0156447972
ssdeep: 12288:Fe0pVdYJHoZ0TcYtEFKghGIAgXwciTjgnx37nmdEqrQf1dzN/PTR/FzQ9R:cmTY1oZBYCFzAxcRxKiqrgHzXFzQf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1250523852AE0D9A4C69EAA70487AD21D73247E601C1D0F4B76EC7BCE1CB198DBBC7458
sha3_384: cc642c0d630c6ae4d2574d25585365a4cae2ffbe49f47a57911a1afdedf95dd6800eb33b18e4ee1fb13155631fd52425
ep_bytes: 9cc704246618661c6088542408c74424
timestamp: 2019-12-25 06:14:02

Version Info:

Translation: 0x0804 0x04b0
CompanyName: Microsoft
ProductName: LOL各大区账号查询
FileVersion: 1.00
ProductVersion: 1.00
InternalName: LOL各大区账号查询
OriginalFilename: LOL各大区账号查询.exe

Ursu.732507 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.732507
ALYacGen:Variant.Ursu.732507
MalwarebytesMalware.Heuristic.1003
VIPREGen:Variant.Ursu.732507
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Generic.c697bbed
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.732507
AvastWin32:Evo-gen [Trj]
EmsisoftGen:Variant.Ursu.732507 (B)
ZillyaTrojan.Generic.Win32.1014194
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.f584a361e6e3dfdd
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Ursu.732507
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Wacatac
XcitiumMalware@#20tbj4qjhjtt4
ArcabitTrojan.Ursu.DB2D5B
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Dynamer!rfn
McAfeeArtemis!F584A361E6E3
Cylanceunsafe
PandaTrj/Genetic.gen
RisingTrojan.Generic@AI.98 (RDMK:mTtbbPxoQz0nlQZ8i/HLNw)
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Generic!tr
BitDefenderThetaGen:NN.ZevbaF.36164.1u0@aWA7u!eb
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.1e6e3d
DeepInstinctMALICIOUS

How to remove Ursu.732507?

Ursu.732507 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment