Malware

Should I remove “Ursu.327276”?

Malware Removal

The Ursu.327276 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.327276 virus can do?

  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.327276?


File Info:

crc32: 1216C312
md5: a82562862dc620fbf82f551e968292f6
name: A82562862DC620FBF82F551E968292F6.mlw
sha1: cefa5ffcbbed748b64718beed22028f323a1d87a
sha256: a22bb189ce9a289bfa3d6d391f77840af961f7c17e4a5929af6bcefdef382a72
sha512: 94e226504cc78f7490fb0d36f2ed987ee05012b604f75b97baade84e46c88929541799c5ac1fd7cdd35f9fa2573f97a7dfdfd68b4368a074798ec0d52ba773a6
ssdeep: 24576:tflGPhQnWkkeCTJdIEFFA0t2/06bFhx/q8DOE0l8KcFAsi5D:tflGPhQnywEj2/DFW
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7edfx4e00x767bx5f55x5668x63d2x4ef61.0
FileVersion: 1.0.0.0
CompanyName: x7edfx4e00x767bx5f55x5668x63d2x4ef61.0
Comments: x7edfx4e00x767bx5f55x5668x63d2x4ef61.0
ProductName: x7edfx4e00x767bx5f55x5668x63d2x4ef61.0
ProductVersion: 1.0.0.0
FileDescription: x7edfx4e00x767bx5f55x5668x63d2x4ef61.0
Translation: 0x0804 0x04b0

Ursu.327276 also known as:

MicroWorld-eScanGen:Variant.Ursu.327276
ALYacGen:Variant.Ursu.327276
CylanceUnsafe
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FlyStudio.HackTool.A potentially unwanted
APEXMalicious
GDataWin32.Application.FlyStudio.F
BitDefenderGen:Variant.Ursu.327276
Ad-AwareGen:Variant.Ursu.327276
ComodoTrojWare.Win32.Agent.OSCF@5rs7jr
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.th
FireEyeGeneric.mg.a82562862dc620fb
EmsisoftGen:Variant.Ursu.327276 (B)
SentinelOneDFI – Malicious PE
F-ProtW32/Agent.EW.gen!Eldorado
Endgamemalicious (high confidence)
Antiy-AVLGrayWare/Win32.FlyStudio.a
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Ursu.D4FE6C
Acronissuspicious
McAfeeArtemis!A82562862DC6
MAXmalware (ai score=89)
VBA32HackTool.Sniffer.WpePro
RisingTrojan.Generic@ML.100 (RDML:XThhg5fe5hwIvpJhQ6Uyog)
FortinetW32/Kryptik.FYCN!tr
Qihoo-360Win32/Trojan.e79

How to remove Ursu.327276?

Ursu.327276 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment