Malware

Ursu.354866 information

Malware Removal

The Ursu.354866 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.354866 virus can do?

  • Presents an Authenticode digital signature
  • Attempts to connect to a dead IP:Port (9 unique times)
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

news.7654.com
miniapi.7654.com
show.g.mediav.com
news.toutiaobashi.com
hm.baidu.com
tt-img.7654.com
ocsp.globalsign.com
s3m3.nzwgs.com
max-l.mediav.com
s3.nzbdw.com
s3m3.fenxi.com
ssxd.mediav.com
ocsp2.globalsign.com
crl.globalsign.com

How to determine Ursu.354866?


File Info:

crc32: F3C6910F
md5: 749e565d1b73b790faee66fcb391250b
name: ktnews-5.exe
sha1: 27d7e2b8512f65364079d62a7788990dfe57684e
sha256: 8701f76145545bb178704ffb16d8a1deb8065b9884b0a759fe83aef6d8181705
sha512: 11aaf8646fb7551c2c6bebf59c33c098ac0f9f7180c7c6926e70edbf715e821a2f20ef32731b689f4fadf4ef00ebf143fe6e93b3367bae7a77e2ee9c66208a0b
ssdeep: 24576:QWqm0bR3c4XumAASvkCCshmttEghvto92D9wbMhT1iqSbtpKxoao:HsRx+mAAaCshAtEyvtq/wT15LxBo
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2018
InternalName: x6700x65b0x4fc3x9500
FileVersion: 1.0.0.4
ProductName: x6700x65b0x4fc3x9500
ProductVersion: 1.0.0.4
FileDescription: x6700x65b0x4fc3x9500
OriginalFilename: x6700x65b0x4fc3x9500
Translation: 0x0804 0x04b0

Ursu.354866 also known as:

BkavW32.HfsAdware.C51A
CAT-QuickHealTrojan.Ursu
ZillyaAdware.KuaiZip.Win32.122
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
Invinceaheuristic
CyrenW32/Application.KKUV-5015
SymantecPUA.Gen.2
TrendMicro-HouseCallTROJ_GEN.R002C0OLA18
AvastWin32:Adware-gen [Adw]
Kasperskynot-a-virus:HEUR:AdWare.Win32.KuaiZip.gen
BitDefenderGen:Variant.Ursu.354866
ViRobotAdware.Kuaizip.1266072.A
RisingPUF.KuaiZip!8.2F40 (CLOUD)
EmsisoftGen:Variant.Ursu.354866 (B)
TrendMicroTROJ_GEN.R002C0OLA18
McAfee-GW-EditionBehavesLike.Win32.PUPXCK.th
AviraADWARE/KuaiZip.lsswl
FortinetAdware/KuaiZip
Endgamemalicious (moderate confidence)
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.KuaiZip.gen
MicrosoftPUA:Win32/KuaiZip
SophosGeneric PUA CH (PUA)
AhnLab-V3Malware/Gen.Generic.C2885502
McAfeeArtemis!749E565D1B73
MAXmalware (ai score=99)
VBA32BScope.Adware.KuaiZip
CylanceUnsafe
YandexPUA.KuaiZip!
IkarusAdWare.KuziTui
eGambitUnsafe.AI_Score_99%
GDataGen:Variant.Ursu.354866
AVGWin32:Adware-gen [Adw]
Cybereasonmalicious.d1b73b
PandaTrj/CI.A
CrowdStrikemalicious_confidence_80% (D)

How to remove Ursu.354866?

Ursu.354866 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment