Malware

Should I remove “Ursu.858883”?

Malware Removal

The Ursu.858883 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.858883 virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Ursu.858883?


File Info:

name: C7024EBB67DFBD89F93B.mlw
path: /opt/CAPEv2/storage/binaries/cda4110af62981e8b3496822ff1d7567a39a539cf399b44094f984734d4bd864
crc32: 01751C9E
md5: c7024ebb67dfbd89f93bd0243ba543bf
sha1: c7faa179b289b611a42f164eb821985c31b3c5f2
sha256: cda4110af62981e8b3496822ff1d7567a39a539cf399b44094f984734d4bd864
sha512: b637da9f61cab341a96d152a4807a94f7f99306df86f668c95f80b2efd1fdef5ec6a1e966516b27db71c9e7ea191f062e4b5c2fc55743e4ceaf8411b7baea827
ssdeep: 96:sfZX9pXW5KgOXOab+CAwLsI/VdQVVZxC6Qidf/Zp8tOrWBcc0wXzNt:sfZD4weY1/LsI/jQbpXN/YIrWBc3wB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T178F1D922A7DC8B7ACE314B36ED2362901B78F760DCE7AF5E6584501ADD933044A63B70
sha3_384: 9d61b243aca7a5fa43d207a3e4d796384c3741179f63c68d066d67f3561cd1067baa63b44d6c9a6e43787a88c2f90146
ep_bytes: ff250020400000000000000000000000
timestamp: 2020-03-26 18:53:40

Version Info:

Translation: 0x0000 0x04b0
FileDescription: clean1
FileVersion: 1.0.0.0
InternalName: clean1.exe
LegalCopyright: Copyright © 2020
OriginalFilename: clean1.exe
ProductName: clean1
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Ursu.858883 also known as:

LionicTrojan.MSIL.Disfa.4!c
MicroWorld-eScanGen:Variant.Ursu.858883
FireEyeGen:Variant.Ursu.858883
ALYacGen:Variant.Ursu.858883
Cylanceunsafe
ZillyaDownloader.Agent.Win32.403484
SangforDownloader.Msil.Disfa.V7sb
K7AntiVirusTrojan-Downloader ( 00544baf1 )
AlibabaTrojan:MSIL/Disfa.50a75aa1
K7GWTrojan-Downloader ( 00544baf1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Dnldr27.BWQS
CyrenW32/MSIL_Agent.BSN.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of MSIL/TrojanDownloader.Agent.FGM
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.MSIL.Disfa.gen
BitDefenderGen:Variant.Ursu.858883
NANO-AntivirusTrojan.Win32.Disfa.hsfjqe
AvastWin32:GenMaliciousA-JOL [Trj]
TencentMsil.Trojan-Downloader.Ader.Mcnw
EmsisoftGen:Variant.Ursu.858883 (B)
F-SecureTrojan.TR/Dldr.Agent.ltgux
DrWebTrojan.DownLoader33.24806
VIPREGen:Variant.Ursu.858883
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
GDataGen:Variant.Ursu.858883
JiangminTrojan.MSIL.oktk
AviraTR/Dldr.Agent.ltgux
Antiy-AVLTrojan/MSIL.Disfa
XcitiumMalware@#3odlra9mbrg7t
ArcabitTrojan.Ursu.DD1B03
ZoneAlarmHEUR:Trojan.MSIL.Disfa.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win32.Wacatac.C4062344
McAfeeArtemis!C7024EBB67DF
MAXmalware (ai score=82)
VBA32Downloader.MSIL.gen.rexp
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
RisingBackdoor.Revetrat!8.E4C1 (CLOUD)
IkarusTrojan-Downloader.MSIL.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.FGM!tr.dldr
BitDefenderThetaGen:NN.ZemsilF.36662.am0@amgulwg
AVGWin32:GenMaliciousA-JOL [Trj]
Cybereasonmalicious.b67dfb
DeepInstinctMALICIOUS

How to remove Ursu.858883?

Ursu.858883 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment