Malware

Ursu.Azorult.816774 removal guide

Malware Removal

The Ursu.Azorult.816774 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.Azorult.816774 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Unusual version info supplied for binary

How to determine Ursu.Azorult.816774?


File Info:

name: E6B9460768F141B36482.mlw
path: /opt/CAPEv2/storage/binaries/45218c48c7105f94bd72a79155cb1cb4d32d7ac6a3805c338aaf2e762d12bc99
crc32: B489E7A8
md5: e6b9460768f141b36482a5677f2a4c9b
sha1: ca0d3b5d191fd4913a5042dbfd5383e865b5dd91
sha256: 45218c48c7105f94bd72a79155cb1cb4d32d7ac6a3805c338aaf2e762d12bc99
sha512: d26479496f1568936aa2e09e40f8dde24d73aa0d71d6f4a63e7df5fd7edc090c80894ebc7b40a8c8a9d6f32ca9ad126b6751c5da45ed6caf62ed2f48b0f10d2d
ssdeep: 1536:UD6LfRbvA5HH+wSzSgP9sUwaAjC7eo1/5LGq6jaWrAf2:C6L9onYPrAfoyqenrD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10E73E00CB6A8CA50D92E463B0EE3553440F6FC864931EE27B7CDFB1C0D3B659A985E64
sha3_384: 7a64951ae9d8cb512fadea598a5f14cc6a40f78d84a60c2f5c9afc4214c9d39a98ea3af50d518012261412d25dfdaa80
ep_bytes: ff250020400000000000000000000000
timestamp: 2016-03-26 20:54:29

Version Info:

CompanyName: Windows
FileDescription: Processus hôte pour les services Windows
FileVersion: 4.1.5.​0
InternalName: Chrome.exe
LegalCopyright: Copyright by Microsoft 2016
LegalTrademarks: Windows
OriginalFilename: Chrome.exe
ProductName: Windows
ProductVersion: 4.1.5.​0
Assembly Version: 4.2.4.5
Comments: Modified by an unpaid evaluation copy of Resource Tuner 2 (www.heaventools.com)
Translation: 0x0000 0x04b0

Ursu.Azorult.816774 also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Generic.lXhq
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Ursu.Azorult.816774
FireEyeGeneric.mg.e6b9460768f141b3
ALYacGen:Variant.Ursu.Azorult.816774
CylanceUnsafe
VIPREGen:Variant.Ursu.Azorult.816774
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004b98f01 )
AlibabaTrojan:MSIL/Injector.bb8f3dde
K7GWTrojan ( 004b98f01 )
Cybereasonmalicious.768f14
BitDefenderThetaGen:NN.ZemsilF.34754.em0@amhdPq
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Injector.CET
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ursu.Azorult.816774
AvastMSIL:GenMalicious-AND [Trj]
TencentWin32.Trojan.Generic.Zmhl
Ad-AwareGen:Variant.Ursu.Azorult.816774
EmsisoftGen:Variant.Ursu.Azorult.816774 (B)
ZillyaTrojan.Injector.Win32.1013339
McAfee-GW-EditionBehavesLike.Win32.Generic.lc
Trapminemalicious.high.ml.score
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Ursu.Azorult.816774
JiangminTrojan.Generic.gxlwy
GoogleDetected
AviraTR/Dropper.MSIL.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.50FE
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Ursu.Azorult.DC7686
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
Acronissuspicious
McAfeeArtemis!E6B9460768F1
MalwarebytesTrojan.Injector
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:3OB+U+QrZ11iKsciOWBX8A)
IkarusTrojan.MSIL2
FortinetW32/CET!tr
AVGMSIL:GenMalicious-AND [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ursu.Azorult.816774?

Ursu.Azorult.816774 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment