Malware

Ursu.912476 (file analysis)

Malware Removal

The Ursu.912476 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.912476 virus can do?

  • Sample contains Overlay data
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Ursu.912476?


File Info:

name: 3E5E83046B6C77EC1DBC.mlw
path: /opt/CAPEv2/storage/binaries/000eff29d0aab82efc49c465d0af3f8e857fec54f65d21e1ee22b8435d866499
crc32: 2E0DC42A
md5: 3e5e83046b6c77ec1dbcb424a2f8c2ff
sha1: b77157a4c4af896c8815ec19121b038e5b823d94
sha256: 000eff29d0aab82efc49c465d0af3f8e857fec54f65d21e1ee22b8435d866499
sha512: 901d4867590ddc3d8fa0bba2ceecc70d7b17b26c9fea267b362a450578c61171bd43febaa22bb687037302bf76bd13bfdb123bb64ec1e2e12733de56625dd3a6
ssdeep: 12288:ILeBOIJI5D6JE7hytfjgWBwuJrN/Bhv8tAA/Ar2w+/BIGTDCkRh/vQaidNmSh4h/:s6JkhyRNMeifylaIPqR+FreerZxU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CC152B8D7F5ABB3ED2C9983968919381BB88D050418FFB721D9CDA0815C34BADDD938D
sha3_384: ec42843c001df9196ff04d79f1d65c9921f3237e1dcf8d60163c816b8a3004b7e1e2fcbad1ab493cf95d66bf88b722d0
ep_bytes: ff250020400000000000000000000000
timestamp: 2016-03-18 20:50:37

Version Info:

0: [No Data]

Ursu.912476 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.912476
FireEyeGeneric.mg.3e5e83046b6c77ec
McAfeeTrojan-FIOC!3E5E83046B6C
CylanceUnsafe
VIPREGen:Variant.Ursu.912476
SangforTrojan.Win32.Malware.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Bladabindi.dbb8135a
K7GWTrojan ( 0055e3e31 )
K7AntiVirusTrojan ( 0055e3e31 )
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32MSIL/Bladabindi.BC
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:Trojan.Win32.GenericML.xnet
BitDefenderGen:Variant.Ursu.912476
NANO-AntivirusTrojan.Win32.Dwn.ebbgfw
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10c2aff1
Ad-AwareGen:Variant.Ursu.912476
ComodoMalware@#3eiviqh7fgaz2
DrWebTrojan.DownLoader19.59795
ZillyaTrojan.Reconyc.Win32.16678
TrendMicroTROJ_BLADABINDI_FC280044.UVPM
McAfee-GW-EditionTrojan-FIOC!3E5E83046B6C
SophosMal/Generic-S
IkarusTrojan.MSIL.Bladabindi
GDataGen:Variant.Ursu.912476
JiangminBackdoor.Androm.fkw
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1209191
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.3C54
AhnLab-V3Malware/Win32.RL_Generic.C4320305
BitDefenderThetaGen:NN.ZemsilF.34582.3mY@aCpn08g
ALYacGen:Variant.Ursu.912476
VBA32Backdoor.Androm
TrendMicro-HouseCallTROJ_BLADABINDI_FC280044.UVPM
RisingTrojan.Generic/MSIL@AI.98 (RDM.MSIL:i7icENw2orJCQ3BOWx0a9Q)
YandexTrojan.Reconyc!7ina8gs3Vpo
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Bladabindi.BC!tr
AVGWin32:Malware-gen
Cybereasonmalicious.46b6c7
PandaTrj/GdSda.A

How to remove Ursu.912476?

Ursu.912476 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment