Malware

Ursu.27761 (file analysis)

Malware Removal

The Ursu.27761 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.27761 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Performs some HTTP requests
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
geremyoii.com
netfrronttq.com
edgedl.gvt1.com

How to determine Ursu.27761?


File Info:

crc32: 28DD864B
md5: af3462630a90c3e85f0f0b4c3610ef3a
name: AF3462630A90C3E85F0F0B4C3610EF3A.mlw
sha1: 9054d2d6fd10a733daca6cd225025833d3f9418c
sha256: ccd7c0c6fe2004bf3405df6d756b310ac16c1ab6cb70666dc2f50acf7d84d6df
sha512: c8cedb468795b8121e25b334d3bcc6fbf4b62e399aa721b218e16e7b34bb4c1ac5279dd57b7fdae36d0a3ce80f1ec52817137b23954837fc30176e67656deff3
ssdeep: 1536:mWqsjO7gkmAZTE5XA6QiQJMapoaqRcXKW71L7eplORnTwzjXzvh1BhFx81dqDBI:mXscg9AZY5XJQG7asukTcwvXrDBItbU
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Soldo
InternalName: gunges
FileVersion: 3.4
CompanyName: Soldo
ProductName: gunges souse
ProductVersion: 3.4
FileDescription: gunges coyly
OriginalFilename: gunges.exe
Translation: 0x0409 0x04b0

Ursu.27761 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.27761
FireEyeGeneric.mg.af3462630a90c3e8
CAT-QuickHealTrojan.Cve20151701
ALYacGen:Variant.Ursu.27761
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Ursu.27761
BitDefenderThetaAI:Packer.44D445C221
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyExploit.Win32.CVE-2015-1701.uw
AlibabaExploit:Win32/CVE-2015-1701.f33ad428
NANO-AntivirusExploit.Win32.CVE20151701.evlrnx
RisingTrojan.Generic@ML.95 (RDMK:BOPdHL7rmxr5Kv/w2C3LCQ)
Ad-AwareGen:Variant.Ursu.27761
EmsisoftGen:Variant.Ursu.27761 (B)
F-SecureHeuristic.HEUR/AGEN.1121416
DrWebTrojan.Siggen6.58358
ZillyaExploit.CVE.Win32.2013
TrendMicroTROJ_GEN.R002C0PAC21
McAfee-GW-EditionRansomware-GIX!AF3462630A90
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Talalpek
AviraHEUR/AGEN.1121416
MicrosoftTrojanDownloader:Win32/Talalpek.A
ArcabitTrojan.Ursu.D6C71
ZoneAlarmExploit.Win32.CVE-2015-1701.uw
GDataGen:Variant.Ursu.27761
CynetMalicious (score: 100)
McAfeeRansomware-GIX!AF3462630A90
VBA32BScope.Trojan.Downloader
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
ESET-NOD32a variant of Generik.BINLDXM
TrendMicro-HouseCallTROJ_GEN.R002C0PAC21
TencentWin32.Exploit.Cve-2015-1701.Loho
FortinetW32/Kryptik.EYKI!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Exploit.ca1

How to remove Ursu.27761?

Ursu.27761 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment