Malware

Ursu.844095 removal instruction

Malware Removal

The Ursu.844095 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.844095 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Scheduled file move on reboot detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Ursu.844095?


File Info:

name: 7989A59CEE39FC4AF2F2.mlw
path: /opt/CAPEv2/storage/binaries/0b737fca9e0e0eb1f725c547cd59607ada81c5030526e1b4cf2ed1b8decee849
crc32: D8258486
md5: 7989a59cee39fc4af2f2ff72ce2a0a31
sha1: b4d13896945b40b6e3a7b6fa8e6d5411fd533d98
sha256: 0b737fca9e0e0eb1f725c547cd59607ada81c5030526e1b4cf2ed1b8decee849
sha512: 53b86c16b06821f6363dde009e95bde7d36aee7eccd7bc6c26f6cea68c85e33b02ac9f9489acd8bd53bf4f86ef952089a26df3382c99f8f4810b5ed94c32fec6
ssdeep: 49152:7ymO8Dim/bRdrIPCGOe1R+hU2bnEMTrdqQmaxet1KhEXXC888BLy03xm:G4DimTrACCsU2bFxmoetww3PBLyEm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F9C523429ACBC13DC1358DB0CC2A137049A5FAB5A53B06213269BF4E777E99CC24ED9D
sha3_384: 5accd50d8a6ceab814345db6c43262ba2cda7ef79d69a8ea5d68d5485afc52efb50f1ae519040345f0a40e23e15a198f
ep_bytes: 558bec83c4c453565733c08945f08945
timestamp: 1992-06-19 22:22:17

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Genie-Soft
FileDescription: EditPlus Text Editor Setup
FileVersion:
LegalCopyright:
ProductName: EditPlus Text Editor
ProductVersion: 5.1.2280.13
Translation: 0x0000 0x04b0

Ursu.844095 also known as:

LionicTrojan.Win32.Convagent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.844095
FireEyeGen:Variant.Ursu.844095
McAfeeArtemis!7989A59CEE39
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojan:Win32/Staser.6e5826fb
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.cee39f
ArcabitTrojan.Ursu.DCE13F
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/CrthRazy.R
TrendMicro-HouseCallTROJ_GEN.R002H0CKQ21
KasperskyTrojan.Win32.Staser.elgb
BitDefenderGen:Variant.Ursu.844095
AvastWin32:AdwareX-gen [Adw]
TencentWin32.Trojan.Ursu.Ajcb
Ad-AwareGen:Variant.Ursu.844095
EmsisoftGen:Variant.Ursu.844095 (B)
DrWebTrojan.Siggen9.22670
McAfee-GW-EditionBehavesLike.Win32.AdwareFileTour.vc
SophosMal/Generic-S
APEXMalicious
JiangminTrojan.Staser.eau
AviraHEUR/AGEN.1139446
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Ursu.844095
CynetMalicious (score: 99)
ALYacGen:Variant.Ursu.844095
MAXmalware (ai score=85)
MalwarebytesAdware.DownloadAssistant
FortinetRiskware/CrthRazy
AVGWin32:AdwareX-gen [Adw]

How to remove Ursu.844095?

Ursu.844095 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment