Malware

Ursu.46638 removal guide

Malware Removal

The Ursu.46638 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.46638 virus can do?

  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.46638?


File Info:

crc32: 2AF50B9B
md5: 784e7c79c093334ce64cc17acc5315f0
name: Xenos.exe
sha1: cb3d0516f56972daa95802a25390cad1be51e5d7
sha256: ac714713347ce487689aae2a82e81cece56dd8724cb5475e5e89f7879cb76839
sha512: af9e32d2150b296067e601fd1d9f6f6709ab81f047e151dd25d2608592f1ddd5a9a20d46987b65bf2f6a01874c80389756826ba989c0ea071901106c7e1c422f
ssdeep: 24576:7Ty06VyG5jbqF58+2RooKWbupl5dIDRuwihlfSstLcYJgrjPGsQP8p:xxEjbqF58bjKWQbduFiPSx5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2015
InternalName: Xenos.exe
FileVersion: 2.2.2.0
ProductName: Xenos
ProductVersion: 2.2.2.0
FileDescription: PE injector
OriginalFilename: Xenos.exe
Translation: 0x0400 0x04b0

Ursu.46638 also known as:

MicroWorld-eScanGen:Variant.Ursu.46638
CAT-QuickHealTrojan.Snojan
McAfeeGenericRXBU-XG!784E7C79C093
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Ursu.4!c
SangforMalware
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderGen:Variant.Ursu.46638
K7GWUnwanted-Program ( 004d38111 )
K7AntiVirusUnwanted-Program ( 004d38111 )
Invinceaheuristic
SymantecML.Attribute.HighConfidence
GDataGen:Variant.Ursu.46638
AlibabaHackTool:Win32/Generic.e98589c2
NANO-AntivirusTrojan.Win32.Snojan.eqkpag
RisingTrojan.Generic@ML.86 (RDMK:KIryFQgI0me2FMS4n3ZRKA)
Ad-AwareGen:Variant.Ursu.46638
TACHYONTrojan/W32.Snojan.1090880
EmsisoftGen:Variant.Ursu.46638 (B)
ComodoMalware@#lb78ulevyafa
ZillyaTrojan.Snojan.Win32.864
TrendMicroTROJ_GEN.R002C0PCE20
McAfee-GW-EditionGenericRXBU-XG!784E7C79C093
FireEyeGen:Variant.Ursu.46638
SophosMal/Generic-S
IkarusTrojan.Win32.Snojan
JiangminTrojan.Snojan.tp
WebrootW32.Trojan.Gen
eGambitUnsafe.AI_Score_95%
Antiy-AVLHackTool/Win64.Inject
ArcabitTrojan.Ursu.DB62E
MicrosoftPUA:Win32/CoinMiner
VBA32BScope.Trojan.Tiggre
ALYacGen:Variant.Ursu.46638
MAXmalware (ai score=94)
PandaPUP/Injector
ESET-NOD32a variant of Win32/GameHack.CBV potentially unsafe
TrendMicro-HouseCallTROJ_GEN.R002C0PCE20
YandexTrojan.Snojan!
MaxSecureTrojan.Malware.11033493.susgen
FortinetW32/Kryptik.GAMH!tr
BitDefenderThetaGen:NN.ZexaF.34128.cz1@ayW2@5kO
Cybereasonmalicious.9c0933

How to remove Ursu.46638?

Ursu.46638 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment