Malware

About “Ursu.821267” infection

Malware Removal

The Ursu.821267 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.821267 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Authenticode signature is invalid

How to determine Ursu.821267?


File Info:

name: 964F5A3BD227A33785CB.mlw
path: /opt/CAPEv2/storage/binaries/244e0fa912ab81bee740d91275415ef87c6a4c5c531ae84d89277fd51a85a2ac
crc32: 0218F1F2
md5: 964f5a3bd227a33785cb4425626b2a1e
sha1: 74b5dede7c16afd38d6bbb4f7b49ed2e4beed6c1
sha256: 244e0fa912ab81bee740d91275415ef87c6a4c5c531ae84d89277fd51a85a2ac
sha512: d7955931a12dbe556a2af3a8a6013af86fc2cd211ba9d2e200cb6d289d0bdfeede83f4df565893a2b869b5c5b142bf14363a1562411c03f2f7607ffbf8144627
ssdeep: 1536:/5qx3tHJV7qR2GoIHHz42i3mX5/OagMJ/dqJBUwMLzHJG1:AxV2RVoEiiOrM5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17FA3C526B1DAC12FEA564A707D6BD6A9192C3C724B00D60F3B08FB4C2D36D56A43173B
sha3_384: c38a8e89c02048b64a59b67b8d1a8a8c758c9b1a594db5df5e6c043d662dc51a176e575ec67e734b1fd36b8875056b93
ep_bytes: 68b0144000e8eeffffff000000000000
timestamp: 2008-11-11 09:05:05

Version Info:

Translation: 0x0409 0x04b0
CompanyName: MorTal TeaM
ProductName: Project1
FileVersion: 1.00
ProductVersion: 1.00
InternalName: Project2
OriginalFilename: Project2.exe

Ursu.821267 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Zapchast.4!c
MicroWorld-eScanGen:Variant.Ursu.821267
ClamAVWin.Trojan.Zapchast-170
FireEyeGeneric.mg.964f5a3bd227a337
SkyhighVB-BackDoor.a.gen
McAfeeVB-BackDoor.a.gen
ZillyaTrojan.Zapchast.Win32.95083
SangforSuspicious.Win32.Save.vb
AlibabaTrojan:Win32/Zapchast.17ac5ffa
CrowdStrikewin/malicious_confidence_100% (W)
VirITBackdoor.Win32.Generic.AVTH
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/VB.NZJ
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Zapchast.kr
BitDefenderGen:Variant.Ursu.821267
NANO-AntivirusTrojan.Win32.Zapchast.cwmvxg
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.13b18b00
EmsisoftGen:Variant.Ursu.821267 (B)
F-SecureTrojan.TR/Zapchast.77824
DrWebTrojan.Siggen1.21708
VIPREGen:Variant.Ursu.821267
TrendMicroTROJ_ZAPCHAST.BZ
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Ursu.821267
JiangminTrojan.Zapchast.anj
GoogleDetected
AviraTR/Zapchast.77824
MAXmalware (ai score=99)
Antiy-AVLTrojan/Win32.Zapchast
Kingsoftmalware.kb.a.999
XcitiumMalware@#1pxo9idbw4ua4
ArcabitTrojan.Ursu.DC8813
ZoneAlarmTrojan.Win32.Zapchast.kr
MicrosoftTrojan:Win32/Malagent!gmb
VBA32TScope.Trojan.VB
ALYacGen:Variant.Ursu.821267
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_ZAPCHAST.BZ
RisingTrojan.VBInject!1.658A (CLASSIC)
YandexTrojan.GenAsa!sH8171/f+hA
IkarusTrojan.Win32.Zapchast
MaxSecureTrojan.Malware.769161.susgen
FortinetW32/VB_BackDoor.A!tr
BitDefenderThetaAI:Packer.654FD57120
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove Ursu.821267?

Ursu.821267 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment