Malware

Ursu.774720 (B) (file analysis)

Malware Removal

The Ursu.774720 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.774720 (B) virus can do?

  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Ursu.774720 (B)?


File Info:

name: 9EAE29D7276A0F451F89.mlw
path: /opt/CAPEv2/storage/binaries/93682c012d4bff5cebe469ab077c539fdd0d5f2824f6b3478045d28a6ddf4593
crc32: 03D7E2C0
md5: 9eae29d7276a0f451f8963312dbd6c4f
sha1: fbad860bf2f8c7b56813573e1c6e04429a634f11
sha256: 93682c012d4bff5cebe469ab077c539fdd0d5f2824f6b3478045d28a6ddf4593
sha512: a15697362a92da9bb13a2892232d373437097bd88c934ccc98398601a71bc69ef912e42f0153b66fdeaae6b45ada2a2587040ea2b30280d643054579a27e0513
ssdeep: 48:6m1Sb+JShhXIQpGNMIEURb9ihMVHC7/BO0sZi21ZsFtRQlwjIcFipfbNtm:Y+JSrXNpqEUmKs/00sZ9f+juzNt
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T174C194215BE98736EA378B719CF353011278FB138D1BAB5E24D5220F7D277048B62A21
sha3_384: d87a00189c05a9aa6a44fb370952b9f2026c56a5a5910d2e011b884657969b07f5b81b3e7d0900548953729ead5e776d
ep_bytes: ff250020400000000000000000000000
timestamp: 2104-11-15 22:07:29

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: loaders
FileVersion: 1.0.0.0
InternalName: loaders.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: loaders.exe
ProductName: loaders
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Ursu.774720 (B) also known as:

LionicTrojan.MSIL.Stealer.i!c
MicroWorld-eScanGen:Variant.Ursu.774720
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
McAfeeRDN/Generic PWS.y
SangforInfostealer.MSIL.Stealer.gen
K7AntiVirusTrojan-Downloader ( 00588f451 )
AlibabaTrojanPSW:MSIL/Stealer.e7c75fdd
K7GWTrojan-Downloader ( 00588f451 )
Cybereasonmalicious.7276a0
BitDefenderThetaGen:NN.ZemsilF.34182.am0@aCrIQqk
SymantecML.Attribute.HighConfidence
ESET-NOD32MSIL/TrojanDownloader.Tiny.BHR
TrendMicro-HouseCallTROJ_GEN.R002C0WJ621
Paloaltogeneric.ml
CynetMalicious (score: 99)
KasperskyHEUR:Trojan-PSW.MSIL.Stealer.gen
BitDefenderGen:Variant.Ursu.774720
AvastWin32:Malware-gen
TencentMsil.Trojan-qqpass.Qqrob.Hxqk
EmsisoftGen:Variant.Ursu.774720 (B)
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R002C0WJ621
McAfee-GW-EditionRDN/Generic PWS.y
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1206892
MicrosoftTrojan:Win32/Wacatac.B!ml
ViRobotTrojan.Win32.Z.Ursu.5632.AV
ZoneAlarmHEUR:Trojan-PSW.MSIL.Stealer.gen
GDataGen:Variant.Ursu.774720
AhnLab-V3Malware/Win.Generic.C4700288
MAXmalware (ai score=89)
MalwarebytesTrojan.Downloader.MSIL.Generic
APEXMalicious
FortinetMalicious_Behavior.SB
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Ursu.774720 (B)?

Ursu.774720 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment