Malware

How to remove “Ursu.846769”?

Malware Removal

The Ursu.846769 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.846769 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • Writes a potential ransom message to disk
  • CAPE detected the PyInstaller malware family

How to determine Ursu.846769?


File Info:

name: DD95A685EF6F8DE1D0A4.mlw
path: /opt/CAPEv2/storage/binaries/8b4f3e227ade8a81490c4ad783837cdc6436bd23931f5db44e7e6923e70a669a
crc32: 28CA2A93
md5: dd95a685ef6f8de1d0a45d474acabd11
sha1: fdd68d2efb195461158f67c6be4e9d91fc82030b
sha256: 8b4f3e227ade8a81490c4ad783837cdc6436bd23931f5db44e7e6923e70a669a
sha512: d152b42c0dd28abda4177623a28f31bf83d335d9eb59aff22ec5eaa060d9fd2a54b205938cc8efbff94f17f733076921bfdf572d303e593537cec8910c6222dc
ssdeep: 196608:qv9xyWpu62/XE5HTDJg5+EmoRlb0e6MyBVXrm7b5DfLH+c:qvppu620XJcgeme6MyBV7ULH+c
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19D963336A8A1ECFDE0F39D3909BDCF346DBA6A610B11E54FC628D7710ED1AD190181A7
sha3_384: 0822a6152e63adc15ac1dc0777a35bac3e6daaa4a1ddc5f4f6ae2bcfc234438e3f7d96fca50fb6ce86eb515cd847636c
ep_bytes: e819050000e98efeffffcccccc575653
timestamp: 2019-07-09 14:23:33

Version Info:

0: [No Data]

Ursu.846769 also known as:

MicroWorld-eScanGen:Variant.Ursu.846769
FireEyeGeneric.mg.dd95a685ef6f8de1
ALYacGen:Variant.Ursu.846769
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Occamy.C8B
K7AntiVirusTrojan ( 005675e11 )
AlibabaTrojan:Application/CoinMiner.8bdc05a0
K7GWTrojan ( 005675e11 )
Cybereasonmalicious.5ef6f8
SymantecML.Attribute.HighConfidence
ESET-NOD32Python/CoinMiner.AQ
Paloaltogeneric.ml
BitDefenderGen:Variant.Ursu.846769
AvastFileRepMalware
Ad-AwareGen:Variant.Ursu.846769
SophosMal/Generic-S
ComodoMalware@#2zsnyrn7ukl8s
McAfee-GW-EditionBehavesLike.Win32.Trojan.rc
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Variant.Ursu.846769 (B)
APEXMalicious
GDataGen:Variant.Ursu.846769
eGambitUnsafe.AI_Score_92%
AviraHEUR/AGEN.1202300
MicrosoftTrojan:Win32/Occamy.C8B
CynetMalicious (score: 100)
McAfeeArtemis!DD95A685EF6F
MAXmalware (ai score=89)
IkarusTrojan.Python.CoinMiner
FortinetW32/CoinMiner.AQ!tr
WebrootW32.Malware.Gen
AVGFileRepMalware

How to remove Ursu.846769?

Ursu.846769 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment