Malware

Ursu.777608 (B) removal tips

Malware Removal

The Ursu.777608 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.777608 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Ursu.777608 (B)?


File Info:

name: E10BB19C102CEAE91CF5.mlw
path: /opt/CAPEv2/storage/binaries/3f89d79ff2d890717ca69c2312648f69401b09a5292576c0a9f318e8977cb66d
crc32: 85A3044E
md5: e10bb19c102ceae91cf5351034ea60f2
sha1: 718b0b0f346f7c07918353bf2eb69a27a943b1c9
sha256: 3f89d79ff2d890717ca69c2312648f69401b09a5292576c0a9f318e8977cb66d
sha512: d4cc47bb43a53a012896f64b92c55cbef09adab29726a74b9b6c3a8ff6374327cc73ea82c9dd5530d2118f4f8439911750048d894cd542a2340efd94918cf7d5
ssdeep: 196608:eQbylRnkOODU0JlSgj9t0rcQr5Dn77U0PdfIRzVLzQdI6htq:Kl9MP19KQQr5DnvU0VARxo+6fq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AB763366544374A4F8D35D34A21DF8EA290E3A771E5BBD714C0ACCE9843ACC3E6D621B
sha3_384: a232eccf49bb9baa328bee617704d50fead6a55776ce2acac004ec974646646e3eea36181282343ccbe9195c4a70d20c
ep_bytes: 60be00d05f008dbe0040e0ff5783cdff
timestamp: 2020-03-12 10:39:35

Version Info:

FileVersion: 7.3.2.3
FileDescription: 大千登录器
ProductName: Dengluq.dll
ProductVersion: 7.3.2.3
CompanyName: 大千软件
LegalCopyright: 大 千 版权所有(C) 2010-2011
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Ursu.777608 (B) also known as:

LionicTrojan.Win32.Ursu.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Ursu.777608
ALYacGen:Variant.Ursu.777608
CylanceUnsafe
Cybereasonmalicious.c102ce
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Genericrxal-9885335-0
BitDefenderGen:Variant.Ursu.777608
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Ursu.777608
EmsisoftGen:Variant.Ursu.777608 (B)
VIPREGen:Variant.Ursu.777608
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
FireEyeGeneric.mg.e10bb19c102ceae9
SophosGeneric PUA HB (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Application.PUPStudio.A
Antiy-AVLTrojan/Generic.ASCommon.FA
ArcabitTrojan.Ursu.DBDD88
MicrosoftTrojan:Win32/Occamy.C3F
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.HDC.C151803
McAfeeArtemis!E10BB19C102C
MAXmalware (ai score=86)
VBA32BScope.Trojan.Tonmye
MalwarebytesMalware.Heuristic.1003
RisingTrojan.ELang!1.64ED (CLOUD)
IkarusPUA.Virbox
MaxSecureDropper.Dinwod.frindll
FortinetW32/CoinMiner.65CA!tr
BitDefenderThetaGen:NN.ZexaF.34806.@pKfaqi!pEib
AVGWin32:Malware-gen
CrowdStrikewin/grayware_confidence_60% (W)

How to remove Ursu.777608 (B)?

Ursu.777608 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment