Malware

Ursu.882261 information

Malware Removal

The Ursu.882261 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.882261 virus can do?

  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid

How to determine Ursu.882261?


File Info:

name: 7DCE13EEFD466810B984.mlw
path: /opt/CAPEv2/storage/binaries/08a0e92760d093ab109f2d1cbf6cb155eec8dd44a6a8c4e24690974955b9e733
crc32: B69F7F1C
md5: 7dce13eefd466810b984ea18d7059826
sha1: 9a65230217aeb6bcb14dfaad93d71947a6782b67
sha256: 08a0e92760d093ab109f2d1cbf6cb155eec8dd44a6a8c4e24690974955b9e733
sha512: 39344d3684253fb3fbb6fd75ec8cd1181c6a5934689088d1ef02119aa5f108143fd3a7276fe7a9f13d0b322862037d4f17b6eeedb91badc7325a07856d8f7e75
ssdeep: 196608:3IEeqvAluKf/LU/SRrZYID4LnY+lEJuBSYXEDdz9:Fv4wKf/wm2IA1ltBdm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15E663313A1A26523C2750ABB2ABB7F3EC7F24071E11D020EEB513D77B826EAE1558558
sha3_384: e9d343582897b17c6cf8d2a7cba3e114157583f98c521efa428209f59a23aac6fa36c6c0591cb61c33b695a307717040
ep_bytes: 81ec840100005355565733db68018000
timestamp: 2016-04-02 03:20:05

Version Info:

CompanyName: http://www.utcsoft.com
FileDescription: UTC ESeal Middle V1.2.5.108 简体中文安装包
FileVersion: 1.2.5.108
LegalCopyright: UTC Soft, Inc.
LegalTrademarks:
ProductName: UTC ESeal Middle
Translation: 0x0804 0x03a8

Ursu.882261 also known as:

LionicTrojan.Win32.Generic.4!c
FireEyeTrojan.GenericKD.35667890
CAT-QuickHealTrojan.MsilFC.S19436105
McAfeeArtemis!7DCE13EEFD46
CylanceUnsafe
SangforTrojan.Win32.Ymacco.AABE
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.efd466
SymantecML.Attribute.HighConfidence
ESET-NOD32BAT/HostsChanger.A potentially unsafe
APEXMalicious
Paloaltogeneric.ml
BitDefenderTrojan.GenericKD.35667890
NANO-AntivirusTrojan.Win32.Dnoper.hqzrzj
ViRobotTrojan.Win32.Z.Ursu.6800797
AvastWin32:Malware-gen
TencentMsil.Trojan.Dnoper.Amda
SophosMal/Generic-S
ComodoMalware@#1b970qne5llg7
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
EmsisoftTrojan.GenericKD.35667890 (B)
GDataGen:Variant.Ursu.882261
JiangminTrojan.MSIL.yqvj
AviraTR/Redcap.elwld
Antiy-AVLTrojan/Generic.ASMalwS.30856C9
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
ALYacGen:Variant.Ursu.882261
MAXmalware (ai score=86)
VBA32TScope.Trojan.MSIL
TrendMicro-HouseCallTROJ_GEN.R002H01L321
YandexTrojan.Dnoper!BW8DasB9xBw
FortinetPossibleThreat
AVGWin32:Malware-gen

How to remove Ursu.882261?

Ursu.882261 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment