Malware

Should I remove “Ursu.394247”?

Malware Removal

The Ursu.394247 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.394247 virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Queries information on disks, possibly for anti-virtualization
  • Checks the version of Bios, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
www.virtualhardwares.com
a.tomx.xyz

How to determine Ursu.394247?


File Info:

crc32: F6F312DC
md5: ce3542a69d477fe4b981000b2feb8b7e
name: gta.exe
sha1: 7a3b2bbf558deaed11bbf0a7f442e3cc7d47ed2f
sha256: d82d9d873faf7e73c0c0d66e7b6d80cc0667e5e981ae40c07656d47bf9716c1f
sha512: 79b0fbc3c2b2d4e8b11ff30a2657cf11254596bce17a340646dd0fb3b76e2bc6f383ce1504609cc24065a2904af744df43570d23a58e4b08ed73c2ea95be26c3
ssdeep: 49152:pNQ6j0NQSd6vuoFF7x9jDR3lUPmdm7OTOMsf7deXHBo0Ms:pNQ6oNQSd6vuoZtF1wmdmgfwxOBo0Ms
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) virtualhardwares All Rights Reserved
InternalName: hardware.exe
FileVersion: 1, 0, 0, 0
CompanyName: hardware
ProductName: hardware
ProductVersion: 1, 0, 0, 0
FileDescription: hardware
OriginalFilename: hardware
Translation: 0x0409 0x04b0

Ursu.394247 also known as:

MicroWorld-eScanGen:Variant.Ursu.394247
CAT-QuickHealPUA.TiggreRI.S5688571
McAfeeArtemis!CE3542A69D47
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderGen:Variant.Ursu.394247
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.69d477
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataGen:Variant.Ursu.394247
SUPERAntiSpywareTrojan.Agent/Gen-Emotet
RisingTrojan.Generic@ML.100 (RDML:a8dHgQfhJE3DafGw4n+wWA)
Endgamemalicious (high confidence)
SophosMal/Generic-S
TrendMicroTROJ_GEN.R015C0PK619
McAfee-GW-EditionBehavesLike.Win32.Ramnit.tc
FireEyeGeneric.mg.ce3542a69d477fe4
EmsisoftGen:Variant.Ursu.394247 (B)
WebrootW32.Malware.gen
Antiy-AVLTrojan/Win32.Occamy
ArcabitTrojan.Ursu.D60407
AegisLabTrojan.Win32.Ursu.4!c
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
VBA32BScope.Trojan.Rootkit
ALYacGen:Variant.Ursu.394247
MAXmalware (ai score=82)
Ad-AwareGen:Variant.Ursu.394247
PandaTrj/Genetic.gen
ZonerTrojan.Win32.69202
TrendMicro-HouseCallTROJ_GEN.R015C0PK619
YandexTrojan.Agent!HX53rQKn4us
SentinelOneDFI – Suspicious PE
FortinetW32/Generic.AP.1D85A8!tr
BitDefenderThetaGen:NN.ZexaCO3.32248.Lv0@aiyFEmcl
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_80% (W)
Qihoo-360Win32/Trojan.0d6

How to remove Ursu.394247?

Ursu.394247 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment