Malware

How to remove “Ursu.744631 (B)”?

Malware Removal

The Ursu.744631 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.744631 (B) virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect

How to determine Ursu.744631 (B)?


File Info:

name: 6F14DCFB307F4F9D9FE0.mlw
path: /opt/CAPEv2/storage/binaries/b1fec85f2708e55f07e6301f8ac4f61457d8b5706dc72705d89a9001ee90ca5d
crc32: C06B5613
md5: 6f14dcfb307f4f9d9fe04c277f9e6e73
sha1: c1b3cf0ee07b96678b27f546a914cd4501c11b25
sha256: b1fec85f2708e55f07e6301f8ac4f61457d8b5706dc72705d89a9001ee90ca5d
sha512: 8ef3c25434c004c2cdf3f07e4e632b42feb180ed740d34f4b5506ee0d387b12bbf0c34ce63250f64fef62de94843ec8a20e62887db0647d06818555b39ce9d80
ssdeep: 6144:RaygbSvoQ1X55LSv1Ic38IdAVT5z+i8gPXR1r2qC4mSTN+jjeyRLq:4SvRX55Lm1LsLzEg5xC4BSE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B0E46B32A2BC916BCA907378AC1960519EAD7F1FB7478E3B30797F95E930050DF091A9
sha3_384: bfe34c158e1a71218ee843cb1e9646cad214109be6294704f35ce6fd65d75528963445440f1831199e062dad68c3cfce
ep_bytes: ff2500a04700302a0030190040e10000
timestamp: 2020-05-01 16:16:15

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription:
FileVersion: 0.0.0.2
InternalName: DarkSidecc CCGen V0.2 Desktop.exe
LegalCopyright:
LegalTrademarks:
OriginalFilename: DarkSidecc CCGen V0.2 Desktop.exe
ProductName:
ProductVersion: 0.0.0.2
Assembly Version: 0.0.0.2

Ursu.744631 (B) also known as:

LionicTrojan.Win32.Ursu.4!c
Elasticmalicious (high confidence)
ALYacGen:Variant.Ursu.744631
SangforTrojan.Win32.Wacatac.D
K7AntiVirusTrojan ( 7000001c1 )
AlibabaTrojan:MSIL/VMProtBad.19dcb863
K7GWTrojan ( 7000001c1 )
Cybereasonmalicious.b307f4
ESET-NOD32a variant of MSIL/Packed.VMProtect.C suspicious
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.MSIL.Crypt.gen
BitDefenderGen:Variant.Ursu.744631
NANO-AntivirusTrojan.Win32.Crypt.iwjedt
MicroWorld-eScanGen:Variant.Ursu.744631
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Ursu.744631
EmsisoftGen:Variant.Ursu.744631 (B)
ComodoMalware@#13nz9lzwe5bzg
DrWebTrojan.Siggen12.52497
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0RLC21
McAfee-GW-EditionBehavesLike.Win32.Generic.jm
FireEyeGeneric.mg.6f14dcfb307f4f9d
SophosMal/VMProtBad-A
IkarusTrojan.MSIL.Vmprotect
GDataGen:Variant.Ursu.744631
JiangminTrojan.MSIL.ownq
AviraTR/Kryptik.iemhd
Antiy-AVLTrojan/Generic.ASMalwS.328D6BF
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Ursu.DB5CB7
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win.Generic.C4408227
McAfeeArtemis!6F14DCFB307F
MAXmalware (ai score=85)
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002C0RLC21
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.11716371.susgen
FortinetMSIL/Crypt.A!tr
BitDefenderThetaGen:NN.ZemsilF.34160.Ru0@aG6YDEk
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ursu.744631 (B)?

Ursu.744631 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment