Malware

Ursu.204030 (file analysis)

Malware Removal

The Ursu.204030 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.204030 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • The following process appear to have been packed with Themida: CsGO_Skin.exe
  • Network activity detected but not expressed in API logs
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

How to determine Ursu.204030?


File Info:

crc32: BB5A0B79
md5: c47dbcae596c10eb1031745dbe288d4b
name: CsGO_Skin.exe
sha1: 630a3f868f41ce809b1f3cc81cf638fe9262e9a9
sha256: c4771d4aa0a5acae04a1d7d2e37ff3b103379690f556bee2b6c4c2dd25f81e1f
sha512: 957ffbd48f538f247557579fe4a914bcc97ae44efd312303c50250a16320c2efefc23c68028e6b3962c56283ed2e8a933a5664fd39b7b0ab8817bbf93548ff13
ssdeep: 49152:TnI1kB5tAJOKYfAQy6u5gEmTQpqvH6imvZUC1:0KyOKNsLEmMpqPtmvZU
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: www.cheat8.com x7248x6743x6240x6709
FileVersion: 1.2.0.0
CompanyName: www.cheat8.com
Comments: CsGo_Skin
ProductName: CsGo_Skin
ProductVersion: 1.2.0.0
FileDescription: CsGo_Skin
Translation: 0x0804 0x04b0

Ursu.204030 also known as:

BkavW32.HfsAutoB.
MicroWorld-eScanGen:Variant.Ursu.204030
FireEyeGeneric.mg.c47dbcae596c10eb
ALYacGen:Variant.Ursu.204030
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
BitDefenderGen:Variant.Ursu.204030
Cybereasonmalicious.e596c1
BitDefenderThetaGen:NN.ZexaF.34084.Yz0aaGCxtCcb
ESET-NOD32a variant of Generik.FXJZCWH
Paloaltogeneric.ml
GDataGen:Variant.Ursu.204030
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Generic.1fdb56ef
NANO-AntivirusTrojan.Win32.TPM.fdpzbf
AvastWin32:Malware-gen
TencentWin32.Trojan.Agent.Sxof
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Ursu.204030 (B)
F-SecureTrojan.TR/Crypt.TPM.Gen
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SentinelOneDFI – Malicious PE
Trapminemalicious.high.ml.score
SophosMal/Generic-S
APEXMalicious
JiangminTrojan.Generic.cjpbw
AviraTR/Crypt.TPM.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Ursu.D31CFE
AhnLab-V3Malware/Win32.Generic.C2534167
ZoneAlarmHEUR:Trojan.Win32.Generic
Acronissuspicious
McAfeeArtemis!C47DBCAE596C
MAXmalware (ai score=98)
VBA32TScope.Malware-Cryptor.SB
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.Agent!9h3kLP6IfqM
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Generic!tr
Ad-AwareGen:Variant.Ursu.204030
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ursu.204030?

Ursu.204030 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment