Malware

Ursu.740883 removal guide

Malware Removal

The Ursu.740883 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.740883 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Created a process from a suspicious location
  • CAPE detected the NanoCore malware family
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key

How to determine Ursu.740883?


File Info:

name: 4081D94101E4FEB01FB2.mlw
path: /opt/CAPEv2/storage/binaries/7588965a53af53c04ccf29bc1a41e3fe75b33199f12f987b4ad56b61ea32d2f2
crc32: AEE9E5E3
md5: 4081d94101e4feb01fb27801dd51f983
sha1: 6288a22ee2ac5906edba3402cfc426f59e4c5b24
sha256: 7588965a53af53c04ccf29bc1a41e3fe75b33199f12f987b4ad56b61ea32d2f2
sha512: 7284610d6eb7bc1d2ff0cd2648268ec4ac19628718d782acd11cb4687ff300f9b43111d7498ed75248b751df43870e71ecc1df36077ca6a2266707cf211bdca1
ssdeep: 49152:BqclZCkv0i25Zg6Xqz9Za+ljZ5VLIWFw31nRO2h+FxGSO41zUq:pZCkVblFLIZ7O2hcsJ41zUq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A9B512653F80E517D1461A34E87AF6FCAB626EA0FC11A26F2BF0FE17F5345C65A22101
sha3_384: d163e6d4d8ed0fac5e9c66673fc64e9355fb86cff202e429ab46687b847182aa1c454310b254cac417c4e6df5f27938d
ep_bytes: 81ec800100005355565733db68018000
timestamp: 2015-12-27 05:38:46

Version Info:

0: [No Data]

Ursu.740883 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45114076
McAfeeArtemis!4081D94101E4
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforBackdoor.Win32.Bladabindi.8
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderTrojan.GenericKD.45114076
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:Backdoor.MSIL.SpyGate.sb
EmsisoftTrojan.GenericKD.45114076 (B)
ComodoMalware@#1x2k083tgzlue
DrWebProgram.Unwanted.1502
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
FireEyeGeneric.mg.4081d94101e4feb0
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.dpfmm
AviraHEUR/AGEN.1233705
MAXmalware (ai score=85)
Antiy-AVLTrojan/Generic.ASMalwS.1F5380D
MicrosoftBackdoor:MSIL/Noancooe.C
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ursu.740883
CynetMalicious (score: 99)
AhnLab-V3Dropper/Win32.MSIL.C2116236
ALYacGen:Variant.Ursu.740883
VBA32Backdoor.MSIL.NanoBot
RisingBackdoor.Noancooe!8.176 (CLOUD)
YandexTrojan.Disfa!CpARCQFaVPw
IkarusTrojan.AD.Bladabindi
BitDefenderThetaGen:NN.ZexaF.34182.mz1aaC!ZemiG
AVGWin32:Malware-gen
Cybereasonmalicious.101e4f
AvastWin32:Malware-gen

How to remove Ursu.740883?

Ursu.740883 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment