Categories: Malware

Ursu.911177 information

The Ursu.911177 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.911177 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Ursu.911177?


File Info:

name: 9ED7B5FB4DBAB13FA0AA.mlwpath: /opt/CAPEv2/storage/binaries/1e2b3351286c1d31280e6be282585188b08fcdde6e3fe054ca679580be5e3898crc32: A0BAFD91md5: 9ed7b5fb4dbab13fa0aa690669901c2dsha1: 0b904b9857bac8c768cfa1da3fb72dc41844f836sha256: 1e2b3351286c1d31280e6be282585188b08fcdde6e3fe054ca679580be5e3898sha512: 529aa5403ec5bc4a883c1b77211ef84297b1a5dbf8660306dd768cf6511c7bff18ab1ab2fd3170e42b41c9abaf846d024d1a108c8876b7eea5a3513208024bb0ssdeep: 12288:+jiGdZ6hxwu+S7rLnUo6eLizqFRoW9LHEBFBSb0udBm8o+G:+uGShxmS7PUo6LURoW1HoQ0uo+Gtype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T115C423B5B69ADB9DF5C7913F802264614CB2DC1013196F8FA208786A363B3E2D2F17D1sha3_384: 62daa6afc2ccb07d6a47e4dad67e2015de10215d314e0a7f612d6dde7b38a5da23742351c089e934528dc2bfdf62e3ccep_bytes: 60be000046008dbe0010faff57eb0b90timestamp: 2008-06-12 08:51:05

Version Info:

CompanyName: Apple Inc.FileDescription: iTunesHelperFileVersion: 9.0.2.25LegalCopyright: © 2003-2009 Apple Inc. All Rights Reserved.InternalName: iTunesHelperOriginalFilename: iTunesHelper.exeProductName: iTunesProductVersion: 9.0.2.25OLESelfRegister: Translation: 0x0409 0x04e4

Ursu.911177 also known as:

MicroWorld-eScan Gen:Variant.Ursu.911177
McAfee Artemis!9ED7B5FB4DBA
Cybereason malicious.b4dbab
Symantec Trojan.Gen.MBT
Elastic malicious (moderate confidence)
ESET-NOD32 a variant of Win32/Injector.Autoit.YZ
APEX Malicious
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Gen:Variant.Ursu.911177
NANO-Antivirus Trojan.Script.AutoIt.bfxbei
Avast AutoIt:Agent-K [Trj]
Ad-Aware Gen:Variant.Ursu.911177
Emsisoft Gen:Variant.Ursu.911177 (B)
VIPRE Gen:Variant.Ursu.911177
McAfee-GW-Edition BehavesLike.Win32.Dropper.hc
Trapmine malicious.high.ml.score
FireEye Gen:Variant.Ursu.911177
Ikarus Packer.Win32.Krap
GData Gen:Variant.Ursu.911177
Google Detected
Arcabit Trojan.Ursu.DDE749
ZoneAlarm HEUR:Trojan.Win32.Generic
Microsoft Trojan:Win32/Wacatac.B!ml
VBA32 Trojan-Inject.Autoit.Irus
ALYac Gen:Variant.Ursu.911177
MAX malware (ai score=81)
Malwarebytes Malware.Heuristic.1003
Fortinet W32/Autoit.AFS!tr
AVG AutoIt:Agent-K [Trj]

How to remove Ursu.911177?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

What is “Trojan.Generic.30064921”?

The Trojan.Generic.30064921 is considered dangerous by lots of security experts. When this infection is active,…

58 mins ago

How to remove “Adware:Win32/Stapcore”?

The Adware:Win32/Stapcore is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Should I remove “Malware.AI.4293759626”?

The Malware.AI.4293759626 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Zusy.545749 malicious file

The Zusy.545749 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

TrojanSpy:MSIL/Ohona.A removal guide

The TrojanSpy:MSIL/Ohona.A is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Worm.Win32.VBNA.brsj removal instruction

The Worm.Win32.VBNA.brsj is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago