Malware

Ursu.269832 (file analysis)

Malware Removal

The Ursu.269832 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.269832 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Unconventionial language used in binary resources: Spanish (Modern)
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.269832?


File Info:

crc32: 917BA6A6
md5: 0461d9000bddb63d57781b3dee1fff51
name: 0461D9000BDDB63D57781B3DEE1FFF51.mlw
sha1: 9b3ef2dee8108f65f1cbeb4c34f30b554dc10546
sha256: 7e4a0948898248df206229128cae42eda922bf9daabeb4bbbde413f0ae62048a
sha512: b80cec7c5a166c20875104e373a11b954146d3f17d784e33bbdb8ddbc6836101257db5015c590536d8e4a05c12174a6e460d0eff0dc4dd0fde51831533b291f2
ssdeep: 12288:hWOJTysM88u4LCGMfjs+f9QAoLlkjA9MH1m7xZnZhX:EONQRWjT9QA0aIphX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2000 - 2010 Avira GmbH. All rights reserved.
InternalName: Control Center
FileVersion: 10.00.12.28
CompanyName: Avira GmbH
PrivateBuild:
LegalTrademarks: AntiVirxae is a registered trademark of Avira GmbH, Germany.
Comments:
ProductName: AntiVir Desktop
SpecialBuild:
ProductVersion: 10.00.12.28
FileDescription: Antivirus Control Center
OriginalFilename: avcenter.exe
Translation: 0x0409 0x04b0

Ursu.269832 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.269832
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.37971
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaRansom:Win32/Blocker.b8678847
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.EQM
APEXMalicious
AvastWin32:VB-AAVQ [Trj]
ClamAVWin.Trojan.Agent-962024
KasperskyTrojan-Ransom.Win32.Blocker.atow
BitDefenderGen:Variant.Ursu.269832
NANO-AntivirusTrojan.Win32.Blocker.ejmzmy
MicroWorld-eScanGen:Variant.Ursu.269832
TencentWin32.Trojan.Blocker.Dun
Ad-AwareGen:Variant.Ursu.269832
ComodoMalware@#euowe0dvx24b
F-SecureTrojan.TR/ATRAPS.Gen7
BitDefenderThetaAI:Packer.628EC7E121
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Swizzor.hc
FireEyeGeneric.mg.0461d9000bddb63d
EmsisoftGen:Variant.Ursu.269832 (B)
JiangminTrojan.Blocker.fya
WebrootW32.Malware.Gen
AviraTR/ATRAPS.Gen7
MicrosoftTrojan:Win32/Wacatac.B!ml
AegisLabTrojan.Win32.Generic.4!c
ZoneAlarmTrojan-Ransom.Win32.Blocker.atow
GDataGen:Variant.Ursu.269832
McAfeeArtemis!0461D9000BDD
MAXmalware (ai score=99)
PandaGeneric Malware
RisingTrojan.VBInject!1.6541 (CLOUD)
YandexTrojan.Injector!Yp3/OZxsaFI
IkarusTrojan.SuspectCRC
AVGWin32:VB-AAVQ [Trj]

How to remove Ursu.269832?

Ursu.269832 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment