Malware

Ursu.380799 (B) (file analysis)

Malware Removal

The Ursu.380799 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.380799 (B) virus can do?

  • A process attempted to delay the analysis task.
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.380799 (B)?


File Info:

crc32: D2CA5C5B
md5: df919a46da2377f913e99fa5d4997ae9
name: DF919A46DA2377F913E99FA5D4997AE9.mlw
sha1: 03cd2235f0e68f297020dd40ad48395fad78bd8d
sha256: cadbbf76fd42b925147d01cc74e82bc8b2b6b03a82a63ca39d2ef1c2877eb536
sha512: 22870750ef402c958353faefaaa77d4549c3d3a6f1f0bf36da77d881db0d0f5ebdb758e5cef21629f407d80e155dad62de747c472624424436125ba3835e9a61
ssdeep: 6144:u6yGcDQ9yDbvFLST77vuplhJWFFBRCiDMgJerG9EvTAVXEXNSk:aDyyDbNLO/Wj7Wb/cvTyXuNSk
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Ursu.380799 (B) also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.DelShad.4!c
DrWebTrojan.Encoder.26999
CAT-QuickHealRansom.Kraken.S4954668
ALYacTrojan.Ransom.Filecoder
CylanceUnsafe
ZillyaTrojan.DelShad.Win32.1124
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Filecoder.3741e2b1
K7GWTrojan ( 005682331 )
K7AntiVirusTrojan ( 005682331 )
CyrenW32/Trojan.JFOE-3844
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.NUC
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyTrojan.Win32.DelShad.fvs
BitDefenderGen:Variant.Ursu.380799
NANO-AntivirusTrojan.Win32.Encoder.fmbwkq
MicroWorld-eScanGen:Variant.Ursu.380799
TencentWin32.Trojan.Filecoder.Wvkj
Ad-AwareGen:Variant.Ursu.380799
SophosMal/Generic-S
ComodoMalware@#200g1p9cdu731
BitDefenderThetaGen:NN.ZexaF.34142.xmGfaaG9D8nG
McAfee-GW-EditionBehavesLike.Win32.HLLP.fc
FireEyeGeneric.mg.df919a46da2377f9
EmsisoftGen:Variant.Ursu.380799 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Gen.aaz
AviraTR/FileCoder.ytttu
Antiy-AVLTrojan/Generic.ASMalwS.2A73129
MicrosoftRansom:Win32/DelShad
ArcabitTrojan.Ursu.D5CF7F
ZoneAlarmTrojan.Win32.DelShad.fvs
GDataGen:Variant.Ursu.380799
AhnLab-V3Malware/Win32.Generic.C2984409
McAfeeArtemis!DF919A46DA23
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Gen
PandaTrj/GdSda.A
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.114371339.susgen
FortinetW32/Gen.KWA!tr.ransom
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Ursu.380799 (B)?

Ursu.380799 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment