Malware

Ursu.836470 (B) removal guide

Malware Removal

The Ursu.836470 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.836470 (B) virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Ursu.836470 (B)?


File Info:

name: 249835E611538B719F6B.mlw
path: /opt/CAPEv2/storage/binaries/71ae2ee877cc040002c00f1e5b2e0fb216dada51d7cc475db55a865716805b8c
crc32: 191DFC1A
md5: 249835e611538b719f6b5a66c34382ca
sha1: e38d0c9a3792e58ee0b720cbfb98de08b349a9e3
sha256: 71ae2ee877cc040002c00f1e5b2e0fb216dada51d7cc475db55a865716805b8c
sha512: 0a20ead6ee4bff8380bf43df99a3224dc4c7fd0abb8ac1b974263dac4512def8b541921feaccf31c984e73ec7f4c019eb864acd1698a1d84f9a1d545c74cedce
ssdeep: 1536:2i04wMRL4nGWcKqL1JMWQEIotW1KIH7p3L5kJ9YwSwiMOvamtOx41:d04ZRSZiJMDAiVyOvLOx41
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BA2454C4744511A6EDBC9F7476A528B02A6F6DBFF2FD106864C8F93A303D1E0153A98E
sha3_384: 62ef22f6863d3ca722cf2d7093eff1bd18ccf9a7b7bc09cf4fe52fa60aa21e3dc0875d1e80941fb8cb06446d1b2315ef
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-02-23 01:55:54

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription: Skype
FileVersion: 1.0.0.0
InternalName: Skype.exe
LegalCopyright: Copyright © 2021
LegalTrademarks:
OriginalFilename: Skype.exe
ProductName: Skype
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Ursu.836470 (B) also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.836470
FireEyeGeneric.mg.249835e611538b71
CAT-QuickHealTrojan.MSIL
ALYacGen:Variant.Ursu.836470
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:MSIL/Bingoml.47cc7246
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Bingoml.gen
BitDefenderGen:Variant.Ursu.836470
NANO-AntivirusTrojan.Win32.Bingoml.jngnxd
AvastWin32:Malware-gen
TencentMsil.Trojan.Bingoml.Hqvo
Ad-AwareGen:Variant.Ursu.836470
TACHYONTrojan/W32.DN-Agent.226304.V
EmsisoftGen:Variant.Ursu.836470 (B)
ZillyaTrojan.Bingoml.Win32.8772
TrendMicroTROJ_GEN.R002C0PBQ22
McAfee-GW-EditionRDN/Generic.grp
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Ursu.836470
AviraTR/Downloader.Gen9
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C5010717
McAfeeRDN/Generic.grp
MAXmalware (ai score=83)
TrendMicro-HouseCallTROJ_GEN.R002C0PBQ22
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:qXdk7/ofDwcx7jWv0N00jQ)
YandexTrojan.Bingoml!HyVIhONOCtE
IkarusTrojan-Downloader
MaxSecureTrojan.Malware.300983.susgen
FortinetPossibleThreat
BitDefenderThetaGen:NN.ZemsilF.34638.nm0@a08QCNe
AVGWin32:Malware-gen
Cybereasonmalicious.611538
PandaTrj/GdSda.A

How to remove Ursu.836470 (B)?

Ursu.836470 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment