Malware

Ursu.445640 removal guide

Malware Removal

The Ursu.445640 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.445640 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Arabic (Oman)
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

How to determine Ursu.445640?


File Info:

crc32: 53BB4D06
md5: 6e7eaa368dda0793c011375af97fbd76
name: 6E7EAA368DDA0793C011375AF97FBD76.mlw
sha1: 6494e8622e8f1fee67d20ef007eb9f80b0f69766
sha256: 0acefdd5f122d3131d6bdfcc1ba2a90c20fe15554fe7af15d7ba1101f66c9289
sha512: d19ffcdf4d66afa79c1f996fc224acce4e2cf16234b15b1dac36d159f9c268e3500c7d458057ff17dc6a8e8ba80d842359c85218e6fbc095f82a6c1b71a211d5
ssdeep: 24576:b5rJzYhDs2bELshq8DaRk71B0A5J223Kjdv+I71d/W7MvAt7JqV:pJzYhVbEkT5BEJ7TWQvW7J
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersion: 0.0.18845.1
InternalName: Counter-Strike Nexon: Zombies
FileVersion: 0.0.18845.1
OriginalFilename: cstrike.exe
FileDescription: Counter-Strike Nexon: Zombies
Translation: 0x0000 0x04b0

Ursu.445640 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Wacatac
ALYacGen:Variant.Ursu.445640
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaPacked:Win32/Themida.4c18edc9
K7GWTrojan ( 005519d01 )
K7AntiVirusTrojan ( 005519d01 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Themida.FOT
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
BitDefenderGen:Variant.Ursu.445640
MicroWorld-eScanGen:Variant.Ursu.445640
Ad-AwareGen:Variant.Ursu.445640
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZedlaF.34608.az8aaemh1xiG
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
FireEyeGeneric.mg.6e7eaa368dda0793
EmsisoftGen:Variant.Ursu.445640 (B)
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Ymacco.AA0A
GridinsoftTrojan.Heur!.038100A0
ArcabitTrojan.Ursu.D6CCC8
GDataGen:Variant.Ursu.445640
McAfeeArtemis!6E7EAA368DDA
MAXmalware (ai score=81)
VBA32TScope.Malware-Cryptor.SB
MalwarebytesMalware.Heuristic.1003
TrendMicro-HouseCallTROJ_GEN.R002H09C321
RisingTrojan.Generic@ML.94 (RDML:67qAXtky6hwbunghrNlr1w)
IkarusTrojan.Win32.Themida
FortinetW32/PossibleThreat
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HgkASQEA

How to remove Ursu.445640?

Ursu.445640 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment