Malware

About “Ursu.105683” infection

Malware Removal

The Ursu.105683 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.105683 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
booray123.no-ip.biz
sgtsteel.sytes.net
hyp3rsteel.sytes.net
java.com
www.bing.com

How to determine Ursu.105683?


File Info:

crc32: 4E081A8D
md5: aaecee163aa8f4e75e6c845f42868e95
name: AAECEE163AA8F4E75E6C845F42868E95.mlw
sha1: 686cd2ccb5e9deb920b68882ea6b5a5fdf3a7a8e
sha256: d102adeb4e1b1071e19ec154d9057fb2c14ddc503312ae1470593b42ee70a733
sha512: 580d014c9b15bf2f62f72ad82ec8b139cdc2847ca539cdb60821cbb0f4e9e3fc872ad0a9239b4de3aa3d1827ae9ecaa63d73b1de1491f5d32cecf2e454a406a9
ssdeep: 49152:EjSeJnN0NdJu1UgHrnRAST8XrhaRY0T+nqO4P4:Ucd4rn3T8hiVT+ne4
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft 2015
Assembly Version: 1.0.0.0
InternalName: MinecraftWT.exe
FileVersion: 1.0.0.0
CompanyName: Microsoft
ProductName: MinecraftWT
ProductVersion: 1.0.0.0
FileDescription: MinecraftWT
OriginalFilename: MinecraftWT.exe

Ursu.105683 also known as:

K7AntiVirusTrojan ( 00524d9d1 )
LionicTrojan.Win32.Blocker.j!c
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.Ursu.105683
CylanceUnsafe
AlibabaRansom:Win32/Blocker.fde24e2f
K7GWTrojan ( 00524d9d1 )
Cybereasonmalicious.63aa8f
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.DMS
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderGen:Variant.Ursu.105683
NANO-AntivirusTrojan.Win32.Blocker.exerzd
MicroWorld-eScanGen:Variant.Ursu.105683
TencentWin32.Trojan.Generic.Lqoy
Ad-AwareGen:Variant.Ursu.105683
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34142.On0@aCZPGWd
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.aaecee163aa8f4e7
EmsisoftGen:Variant.Ursu.105683 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Blocker.ssaww
Antiy-AVLTrojan/Generic.ASMalwS.24148B7
MicrosoftTrojan:Win32/Tiggre!rfn
GDataGen:Variant.Ursu.105683
McAfeeArtemis!AAECEE163AA8
MAXmalware (ai score=85)
VBA32Trojan-Ransom.Blocker
PandaTrj/GdSda.A
YandexTrojan.DR.Agent!qTSN7LPk7Dc
IkarusTrojan-Ransom.Blocker
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Dropper.TE!tr
AVGWin32:Malware-gen

How to remove Ursu.105683?

Ursu.105683 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment