Malware

Ursu.534401 (B) malicious file

Malware Removal

The Ursu.534401 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.534401 (B) virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.534401 (B)?


File Info:

crc32: 301446E1
md5: d920a29fb724cf3474b9494b0fc4abb3
name: D920A29FB724CF3474B9494B0FC4ABB3.mlw
sha1: e5d8194117a5958723d3b48dcd82e31ed3c21906
sha256: bd2730be8c980b5544600d67fbd9c9fc48ac1d8aaa816f7af57c3746eea9922c
sha512: d5574c76c7ff6efee3361d214d15d651139285a02f7ed73312bac59d5983c9d6ab8b15d0b3b81a0fb7b3da253c1bc40d6865dc1cbaf2f85983d0c12ac5ad504f
ssdeep: 49152:U8bgFs8EmU99ou7fZXJE23d1eXixyOqgiCfvaLCacO:U8bgFslT77xXJ9bJiCnFO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2019
InternalName: PatchUi.exe
FileVersion: 2, 0, 3, 1015
CompanyName: x98d8x4e91x9601x5b98x65b9x8bbax575b
Comments: Www.ChinaPYG.CoM
ProductName: PatchUi
ProductVersion: 2, 0, 3, 1015
FileDescription: Baymax Patcher Tools
OriginalFilename: PatchUi.exe
Translation: 0x0409 0x04b0

Ursu.534401 (B) also known as:

K7AntiVirusUnwanted-Program ( 004d38111 )
Elasticmalicious (high confidence)
CynetMalicious (score: 85)
CAT-QuickHealTrojan.Tapxamy
ALYacGen:Variant.Ursu.534401
CylanceUnsafe
ZillyaTrojan.DllInject.Win32.357
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Baymax.135
K7GWUnwanted-Program ( 004d38111 )
Cybereasonmalicious.fb724c
TrendMicroTROJ_GEN.R005C0DHK20
CyrenW32/Razy.EE.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/DllInject.IZ potentially unsafe
APEXMalicious
Paloaltogeneric.ml
BitDefenderGen:Variant.Ursu.534401
MicroWorld-eScanGen:Variant.Ursu.534401
Ad-AwareGen:Variant.Ursu.534401
SophosGeneric PUA JM (PUA)
ComodoMalware@#15cm40mhcqbr1
F-SecureTrojan.TR/Tapxamy.acgac
VIPRETrojan.Win32.Generic!BT
InvinceaMal/Generic-S
FireEyeGeneric.mg.d920a29fb724cf34
EmsisoftGen:Variant.Ursu.534401 (B)
SentinelOneDFI – Suspicious PE
AviraTR/Tapxamy.acgac
Antiy-AVLTrojan/Win32.SGeneric
MicrosoftTrojan:Win32/Tapxamy.A
ArcabitTrojan.Ursu.D82781
AegisLabTrojan.Win32.Malicious.4!c
GDataGen:Variant.Ursu.534401
AhnLab-V3Malware/Win32.Generic.C3157926
McAfeeGenericR-RBI!D920A29FB724
MAXmalware (ai score=85)
VBA32BScope.Trojan.Wintrim
TrendMicro-HouseCallTROJ_GEN.R005C0DHK20
RisingTrojan.HijcLpk!1.998A (TFE:5:njbc0VRkTcT)
YandexRiskware.Agent!
IkarusPUA.DllInject
MaxSecureTrojan.Malware.74658858.susgen
FortinetRiskware/DllInject
AVGWin32:HacktoolX-gen [Trj]
PandaTrj/Genetic.gen

How to remove Ursu.534401 (B)?

Ursu.534401 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment