Malware

About “Ursu.788297” infection

Malware Removal

The Ursu.788297 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.788297 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Scheduled file move on reboot detected
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ursu.788297?


File Info:

name: E0B6DE1BF85B5597BAEB.mlw
path: /opt/CAPEv2/storage/binaries/02fe04f0f2d3a24d6fa8d77ab53f859e8f4182f29c377a84a9be2ec937aa2dc0
crc32: 0E50D779
md5: e0b6de1bf85b5597baebf59bb903d381
sha1: 2da62db31d35650f809aafb25ca7bbf0a40eaecd
sha256: 02fe04f0f2d3a24d6fa8d77ab53f859e8f4182f29c377a84a9be2ec937aa2dc0
sha512: 19de1d9ff3c0b0590aebb07667a615c46610fa8bba98eb57cb281e9baed726b113ab733102a01d3d9efc6bfb7cde61c3c0a1407457f2259c693768ac636bdb28
ssdeep: 49152:GlP4DOqTeIpD/vyOLaIFhXO0TY2AyU9RgH5NE045jCjA+A:GoKaX7LZmdlCjA+A
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T167B52A1BB302C9EAC4278132858AE331A475FC41B621ED9E3760E71CEAB3D614E5E75D
sha3_384: 18a683c24288b95466a98ee962064200f92e98933bd60f8f06608a61acd351658850901446c58429a39a2d599e33b27b
ep_bytes: 4883ec28488b05f5e01200c700010000
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Ursu.788297 also known as:

DrWebWin32.FloodFix
MicroWorld-eScanGen:Variant.Ursu.788297
FireEyeGeneric.mg.e0b6de1bf85b5597
McAfeeArtemis!E0B6DE1BF85B
BitDefenderGen:Variant.Ursu.788297
Cybereasonmalicious.bf85b5
SymantecTrojan.Gen.6
TrendMicro-HouseCallTROJ_GEN.R002H09KQ21
ClamAVWin.Virus.Pioneer-9111434-0
AlibabaVirus:Win32/Floxif.6653324f
Ad-AwareGen:Variant.Ursu.788297
IkarusWin32.Floxif
AviraW32/Floxif.hdc
GridinsoftRansom.Win64.Wacatac.sa
ALYacGen:Variant.Ursu.788297
MAXmalware (ai score=84)
MalwarebytesMalware.AI.2317982026
FortinetW32/PossibleThreat

How to remove Ursu.788297?

Ursu.788297 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment