Malware

Ursu.840201 (file analysis)

Malware Removal

The Ursu.840201 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.840201 virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ursu.840201?


File Info:

name: C179B32169E1877B59A8.mlw
path: /opt/CAPEv2/storage/binaries/2f5d8f137c7d2c0885e1c8f3f6628c50a7363d1f388a62c52f2d1bd470ba22ba
crc32: AAEBF737
md5: c179b32169e1877b59a8070ae7a9ef2f
sha1: f7b6a7bd07bc072d50ffe59b8400905c17085a06
sha256: 2f5d8f137c7d2c0885e1c8f3f6628c50a7363d1f388a62c52f2d1bd470ba22ba
sha512: 4c984ecd7343515c99fd48337f2e686c679d23f054fa3e505629c3be5ac8544e92836826aa409322c0f3896e1735d8c7227105ca0a14fa092260bc332542b406
ssdeep: 3072:GWYAVrgUCPnAJMD8+X5Vi0IH8nVy0JdztvzamGSRbw+2QkpS1FZpKJGeWgtCMp+:G+gUCND8+2008n80JdYm9Rkp/c1EGOnQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10624F1422EF8D432FAE10E759AB0AB078AB678112C35D65F9710CECD7D70681E928777
sha3_384: 399b3f492c1895e0623b9211028d9de8c676248075011b75262e94ce9a8dd317cedd2779e8cb0cf8e8a06df5901cfa76
ep_bytes: 81ecd4020000535556576a2033ed5e89
timestamp: 2012-02-24 19:20:04

Version Info:

0: [No Data]

Ursu.840201 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Variant.Ursu.840201
FireEyeGen:Variant.Ursu.840201
SkyhighBehavesLike.Win32.Dropper.dc
McAfeeArtemis!C179B32169E1
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R002H09BR24
BitDefenderGen:Variant.Ursu.840201
EmsisoftGen:Variant.Ursu.840201 (B)
VIPREGen:Variant.Ursu.840201
ArcabitTrojan.Ursu.DCD209
GDataGen:Variant.Ursu.840201
ALYacGen:Variant.Ursu.840201
MAXmalware (ai score=88)
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Ursu

How to remove Ursu.840201?

Ursu.840201 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment