Malware

Ursu.917812 malicious file

Malware Removal

The Ursu.917812 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.917812 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Ursu.917812?


File Info:

name: 8F6BB77BDC2D4EC706DB.mlw
path: /opt/CAPEv2/storage/binaries/40703fedcccfb5a1b5d5ae8d6f5b7de0ec7b66fa1f441901a2375347e4648c1a
crc32: 08D0EF69
md5: 8f6bb77bdc2d4ec706db3eca53e08c67
sha1: 284249748c6193306d1671c48fee67f9147a7f11
sha256: 40703fedcccfb5a1b5d5ae8d6f5b7de0ec7b66fa1f441901a2375347e4648c1a
sha512: d7d7fa5777b83b40844e31e4adfcf71c8c926f9780f8713951743af81ba608018a624f80be52e6faab9fac650908dc54ca0f36388ea37157549271c3c05ae912
ssdeep: 12288:pDNK5B25h5yMo6pWKm2vFgKyHiGxI/eXOxILozRzFDX:XiBk/yMdp+9KtteXezlX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T150E423A2E7617147DA2E7A33F6D0B149DCFE13BA0323F6D3221F65596988D24C1443BA
sha3_384: 251100041e3f44347ce18844b98ef3cb91d5edf5ffc39159020db373118dcdee65f34802f52d72418058d36ede84319d
ep_bytes: 60be00c04c008dbe0050f3ff57eb0b90
timestamp: 2005-03-14 13:49:14

Version Info:

CompanyName: Opera Software
FileDescription: Opera Internet Browser
FileVersion: 1190
InternalName: Opera
LegalCopyright: Copyright © Opera Software 1995-2011
OriginalFilename: Opera.exe
ProductName: Opera Internet Browser
ProductVersion: 11.01
Translation: 0x0409 0x04b0

Ursu.917812 also known as:

CynetMalicious (score: 99)
FireEyeGeneric.mg.8f6bb77bdc2d4ec7
McAfeePWS-Zbot.gen.ia
MalwarebytesMalware.Heuristic.1003
VIPREGen:Variant.Ursu.917812
K7AntiVirusTrojan ( 004e52cd1 )
BitDefenderGen:Variant.Ursu.917812
K7GWTrojan ( 004e52cd1 )
ArcabitTrojan.Ursu.DE0134
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Kryptik.KLG
APEXMalicious
ClamAVWin.Trojan.Mikey-9958102-0
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Delphi.fomyxj
MicroWorld-eScanGen:Variant.Ursu.917812
Ad-AwareGen:Variant.Ursu.917812
EmsisoftGen:Variant.Ursu.917812 (B)
DrWebTrojan.Packed.1882
ZillyaTrojan.Kryptik.Win32.3421233
TrendMicroTROJ_KRYPTK.SMH
McAfee-GW-EditionPWS-Zbot.gen.ia
Trapminesuspicious.low.ml.score
SophosMal/FakeAV-GQ
IkarusBackdoor.Win32.Kelihos
AviraDR/Delphi.Gen
MAXmalware (ai score=87)
Antiy-AVLTrojan/Generic.ASMalwS.3303
MicrosoftTrojan:Win32/Bulta!rfn
GDataGen:Variant.Ursu.917812
VBA32Trojan.FakeAV.0997
ALYacGen:Variant.Ursu.917812
PandaGeneric Suspicious
TrendMicro-HouseCallTROJ_KRYPTK.SMH
YandexTrojan.DL.FraudLoad!a/61PUByLb8
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/SLM39.A@mm
BitDefenderThetaGen:NN.ZexaF.34806.PmMfaurwrdkS
AVGWin32:Kelihos [Trj]
Cybereasonmalicious.bdc2d4
AvastWin32:Kelihos [Trj]

How to remove Ursu.917812?

Ursu.917812 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment