Malware

Should I remove “Ursu.858202”?

Malware Removal

The Ursu.858202 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.858202 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • CAPE detected the VMProtectStub malware family
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Ursu.858202?


File Info:

name: D7BA576EEF47347DC5A5.mlw
path: /opt/CAPEv2/storage/binaries/2bccc372cedb7076fdde7fe7f1f8175981662dbeab5fa447882ff90c5d6752a7
crc32: 1E912228
md5: d7ba576eef47347dc5a56ed56a7cedb4
sha1: e06c5d384f650c17b7facc3f399f8a4db2fc810c
sha256: 2bccc372cedb7076fdde7fe7f1f8175981662dbeab5fa447882ff90c5d6752a7
sha512: b3e452d04a28ee16ec766e60501d460d205ef126f3427fd0b2524fa9896f8a7075459d1b16ba10a80bfbba0af1e40bd03fa092ebe8760985aa910f04f6a05bc6
ssdeep: 49152:pziLMDGe5qgArGWnKPegZE6MCix6tDFhMF7cadH2fEphkiWZrPzXjoBPGb7rWfi:pZAtPS7M0gFcad2fyCP3oe72
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T146F52327E355553CCC734AF7C460BAE2090DEC3165D485293AB83EEE4B93352BDC69A8
sha3_384: 94968b813b094df2ed1d0e36511c84a1eac58e7475511e5c218b29cd8f1a102b8bb7be52a02e8fa8d0fa38acb2892f58
ep_bytes: 9cc70424c46a783f68b923283d9ce8ea
timestamp: 2013-03-16 05:46:42

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Ursu.858202 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Ursu.858202
SkyhighBehavesLike.Win32.AutoitDropper.wc
ALYacGen:Variant.Ursu.858202
MalwarebytesPUP.Optional.ChinAd
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0056e6e91 )
K7GWTrojan ( 0056e6e91 )
CrowdStrikewin/malicious_confidence_60% (D)
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
CynetMalicious (score: 100)
APEXMalicious
BitDefenderGen:Variant.Ursu.858202
EmsisoftApplication.Generic (A)
VIPREGen:Variant.Ursu.858202
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.d7ba576eef47347d
SophosGeneric ML PUA (PUA)
VaristW32/Trojan.GRW.gen!Eldorado
Kingsoftmalware.kb.b.947
MicrosoftTrojan:Win32/Wacatac.B!ml
XcitiumTrojWare.Win32.Agent.ISVQ@5mbonp
ArcabitTrojan.Ursu.DD185A
GDataGen:Variant.Ursu.858202
GoogleDetected
MAXmalware (ai score=87)
VBA32TrojanPSW.Coins
Cylanceunsafe
RisingTrojan.Generic@AI.99 (RDML:yovS3p9fACbjItKkkmrIVg)
SentinelOneStatic AI – Malicious PE
MaxSecureDropper.Dinwod.frindll
BitDefenderThetaGen:NN.ZexaF.36792.lF0@aafFAylb
Cybereasonmalicious.84f650
DeepInstinctMALICIOUS

How to remove Ursu.858202?

Ursu.858202 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment