Malware

Ursu.863102 information

Malware Removal

The Ursu.863102 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.863102 virus can do?

  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Attempts to disable browser security warnings

How to determine Ursu.863102?


File Info:

crc32: 51747CCE
md5: 860ad0c91816f0c6a68a845a79f28bd7
name: 860AD0C91816F0C6A68A845A79F28BD7.mlw
sha1: 73397638e7b5ade23e0e79f7f2ad4723396530b4
sha256: 7376b3436b36bf126a5462a95341dbf745618ae4f58ffeaf9dcd7a48aa3627f4
sha512: 864d3cc27e099fbe5ba20b96da44d180b0fdb4cb7126c4c50a8a3852b59a915b359cd67f9aae663db6803c24df7457dca9480e473a91835742561cb5a21573a3
ssdeep: 24576:rH4M40zEfpDo8WW7UfKj+Sid6XXCH9uTLg6zNPSWi8ik:xsFpXoETzzNP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ursu.863102 also known as:

BkavW32.AIDetect.malware1
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.863102
CylanceUnsafe
ZillyaAdware.FakeAntiSpy.Win32.90
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/Blocker.c8d26d5d
Cybereasonmalicious.91816f
BitDefenderThetaGen:NN.ZelphiF.34670.rLW@aGOfsPjk
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Adware.FakeAntiSpy.BB
APEXMalicious
AvastWin32:Delf-PPM [Trj]
KasperskyTrojan-Ransom.Win32.Blocker.kxmf
BitDefenderGen:Variant.Ursu.863102
NANO-AntivirusTrojan.Win32.Fakealert.dgrwn
MicroWorld-eScanGen:Variant.Ursu.863102
TencentMalware.Win32.Gencirc.114bc73a
Ad-AwareGen:Variant.Ursu.863102
SophosML/PE-A + Mal/FakeAV-FO
DrWebTrojan.Fakealert.21919
VIPREFraudTool.Win32.FakeVimes!delf (v)
McAfee-GW-EditionBehavesLike.Win32.Infected.th
FireEyeGeneric.mg.860ad0c91816f0c6
EmsisoftGen:Variant.Ursu.863102 (B)
JiangminTrojan.Generic.aafqm
AviraHEUR/AGEN.1114819
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftRogue:Win32/FakePAV
ArcabitTrojan.Ursu.DD2B7E
AegisLabTrojan.Win32.Blocker.j!c
GDataGen:Variant.Ursu.863102
AhnLab-V3Trojan/Win32.FakeAV.C197973
McAfeeFakeAV-PJ.gen.n
MAXmalware (ai score=100)
VBA32TScope.Trojan.Delf
MalwarebytesMalware.AI.1721830571
PandaTrj/CI.A
RisingRansom.Blocker!8.12A (CLOUD)
IkarusTrojan.Win32.FakeAV
FortinetW32/FakeAV.DLCP!tr
AVGWin32:Delf-PPM [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASOQA

How to remove Ursu.863102?

Ursu.863102 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment