Malware

About “Ursu.816903” infection

Malware Removal

The Ursu.816903 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.816903 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Ursu.816903?


File Info:

name: 903BA858321AAE779FDE.mlw
path: /opt/CAPEv2/storage/binaries/26354ddcad21a31270a5c7cd38d05998599ccd91ada23a1036c81f2b560af319
crc32: 75547FAA
md5: 903ba858321aae779fdebdd2d2fbe46e
sha1: 2c4267c7b53f6d49898408bd3cf0acb645ea1780
sha256: 26354ddcad21a31270a5c7cd38d05998599ccd91ada23a1036c81f2b560af319
sha512: acc713bde94c3fc127d1dde44b630af724fd778d2323c448afca30d160eb4e88bdb75106ee85d83e97c19456be501ec16150b862f244cbfef9ecfdf09c318f4c
ssdeep: 12288:3wxH7oyefZU5Zc41jTV14FHpVEALeK0ve0GvUg/dsvWre3i9AgvvNVR:4bo1CTn17NXvBaasAkvzR
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18BF49DC42241E79EC2D1B2FB586566F433260ECE9A40A516D138BF91387A41FCD6FC9E
sha3_384: 5ac58e64c2b486da8be7cafb82e8ecc00d2b5ddc40fc2156351de466aea4d4afcf47e3c239d812d8e340d3e931b9fc34
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-08-30 05:57:01

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: firefox.exe
LegalCopyright:
OriginalFilename: firefox.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Ursu.816903 also known as:

BkavW32.AIDetectNet.01
CynetMalicious (score: 100)
FireEyeGeneric.mg.903ba858321aae77
MalwarebytesBackdoor.Agent.Generic
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.8321aa
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Injector.YG
APEXMalicious
ClamAVWin.Packed.Trojanx-9891229-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.816903
NANO-AntivirusTrojan.Win32.Inject.dbylvd
MicroWorld-eScanGen:Variant.Ursu.816903
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Variant.Ursu.816903
EmsisoftGen:Variant.Ursu.816903 (B)
DrWebTrojan.Siggen6.63994
VIPREGen:Variant.Ursu.816903
Trapminesuspicious.low.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Ursu.816903
JiangminBackdoor/DarkKomet.ey
AviraTR/Dropper.MSIL.Gen
ArcabitTrojan.Ursu.DC7707
MicrosoftTrojan:Win32/Sabsik.EN.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Zbot.R90985
Acronissuspicious
ALYacGen:Variant.Ursu.816903
MAXmalware (ai score=89)
CylanceUnsafe
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:bBuGC13kFt021zTZllhjtw)
IkarusTrojan.SuspectCRC
MaxSecureTrojan.Malware.300983.susgen
BitDefenderThetaGen:NN.ZemsilF.34606.Um0@aGDdeVp
AVGWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Ursu.816903?

Ursu.816903 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment