Malware

Ursu.320791 removal guide

Malware Removal

The Ursu.320791 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.320791 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.320791?


File Info:

crc32: 13D0A5C2
md5: dd62a4c0dffbc825e2eae2fe7b3bf4fd
name: DD62A4C0DFFBC825E2EAE2FE7B3BF4FD.mlw
sha1: c9066157abc79fbcc59f2c813a0cbc4a479c8c7c
sha256: 8a8c6dfbf9169260e91ad73e35ff02c6b7320a4419815252c9486b5d29ae71d4
sha512: f5238ca3ad60fb1d2be6a382290f01933e27374a1d4cab31451266282c5d9b6c1eb4dca0e6a11a4a27f2954dc9d21ab1bce5655e541f51d378b5dc921962ce42
ssdeep: 24576:k//p32Qt/+LTSy2MPZwEYea2F0WjdENvYHbc9YrAP9KhyeWtq5tiRpFgqXqL6Vqz:iUy+LGy2MUealpSnKaPCS5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2004-2016 Code::Blocks Team
InternalName: Code::Blocks
FileVersion: 16.01.0.0
CompanyName: Code::Blocks Team
ProductVersion: 16.01.0.0
PrivateBuild:
LegalTrademarks: All rights reserved.
Comments: Cross-platform IDE built around wxWidgets, designed to be extensible and configurable. Licensed under GPL3.
ProductName: Code::Blocks
SpecialBuild:
Build: January 2016
FileDescription: Code::Blocks IDE
Users: Unlimited.
Support: mandrav at codeblocks.org
OriginalFilename: codeblocks.exe
Developer: Code::Blocks Team
Translation: 0x0409 0x04e4

Ursu.320791 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.320791
FireEyeGeneric.mg.dd62a4c0dffbc825
ALYacGen:Variant.Ursu.320791
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
K7AntiVirusTrojan ( 700000111 )
BitDefenderGen:Variant.Ursu.320791
K7GWTrojan ( 700000111 )
Cybereasonmalicious.0dffbc
APEXMalicious
ClamAVWin.Dropper.XtremeRAT-9233846-0
KasperskyHEUR:Trojan.Win32.Generic
Ad-AwareGen:Variant.Ursu.320791
F-SecureHeuristic.HEUR/AGEN.1100017
DrWebBackDoor.Orcus.14
InvinceaGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.vm
EmsisoftGen:Variant.Ursu.320791 (B)
WebrootW32.Trojan.Autoit
AviraHEUR/AGEN.1100017
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Wacatac.D8!ml
ArcabitTrojan.Ursu.D4E517
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ursu.320791
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Generic.C1928800
McAfeeArtemis!DD62A4C0DFFB
MalwarebytesTrojan.Injector.AutoIt
PandaTrj/Genetic.gen
ESET-NOD32multiple detections
IkarusVirus.Win32.Agent
eGambitUnsafe.AI_Score_100%
FortinetW32/Injector.CXB!tr
BitDefenderThetaAI:Packer.7FC0B0CA15
AVGFileRepMalware
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360HEUR/QVM10.1.3967.Malware.Gen

How to remove Ursu.320791?

Ursu.320791 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment