Malware

Ursu.9536 removal tips

Malware Removal

The Ursu.9536 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.9536 virus can do?

  • Unconventionial language used in binary resources: Arabic (Saudi Arabia)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ursu.9536?


File Info:

name: 2A1BFB8E6748456B8C3C.mlw
path: /opt/CAPEv2/storage/binaries/1c8f92d7fd26535ee7fb7c707f4116c7815c0ce581a4b43708a56830aec09339
crc32: 25920B1A
md5: 2a1bfb8e6748456b8c3c03a6a41ed056
sha1: be9474d59736788600a97d617d5b150329f3ae69
sha256: 1c8f92d7fd26535ee7fb7c707f4116c7815c0ce581a4b43708a56830aec09339
sha512: 9a4dd604e6fadbea0151b9d456bfbd0c2a9506991fbc4adb7a4c3bc2fe68b2d5422daac1ba3fb13d27358d7f583bf1214304acc9ac4a5b1122df0ca50dbc8183
ssdeep: 384:XCbd1XUe0JJLXk14NmGYAx7r6+A9PfnfLSJ14:XC51keKLXW4NmGDxCj3DSn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T132B2C622C3C14AE4E1862639A0277918916BDE111BD54BCB7F5C75FE2F352C2943B1BB
sha3_384: 07749861a365014e7feaba56e69a5281f1025234cce165afa0ba8d655c82bc6cf6539bfcb7da297bcdda00789d5b605c
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 2014-08-28 22:51:35

Version Info:

CompanyName: Buik
FileDescription: Buik proged
FileVersion: Version 2.1.1
InternalName: Buik
LegalCopyright: Copyright by Nego©
OriginalFilename: Buik
Translation: 0x0409 0x04e3

Ursu.9536 also known as:

BkavW32.AIDetect.malware1
tehtrisGeneric.Malware
DrWebTrojan.Upatre.100
MicroWorld-eScanGen:Variant.Ursu.9536
FireEyeGeneric.mg.2a1bfb8e6748456b
ALYacGen:Variant.Ursu.9536
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
Cybereasonmalicious.e67484
ArcabitTrojan.Ursu.D2540
BitDefenderThetaGen:NN.ZexaF.34712.by0@auRljXkG
CyrenW32/Upatre.NY.gen!Eldorado
Elasticmalicious (high confidence)
APEXMalicious
ClamAVWin.Dropper.Upatre-7613387-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.9536
SUPERAntiSpywareTrojan.Agent/Gen-Upatre
AvastWin32:Downloader-WIH [Trj]
Ad-AwareGen:Variant.Ursu.9536
EmsisoftGen:Variant.Ursu.9536 (B)
ComodoTrojWare.Win32.TrojanDownloader.Upatre.AAL@5iclp5
BaiduWin32.Trojan-Downloader.Waski.a
McAfee-GW-EditionBehavesLike.Win32.Generic.mm
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/HkMain-AZ
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.hiszj
MAXmalware (ai score=82)
MicrosoftTrojan:Win32/PWSZbot.GSB!MTB
GDataGen:Variant.Ursu.9536
CynetMalicious (score: 100)
AhnLab-V3Downloader/Win.FCET.C5159949
Acronissuspicious
McAfeeArtemis!2A1BFB8E6748
MalwarebytesUpatre.Trojan.Downloader.DDS
IkarusTrojan-Downloader.Win32.Upatre
AVGWin32:Downloader-WIH [Trj]
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Ursu.9536?

Ursu.9536 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment