Malware

Ursu.560801 removal instruction

Malware Removal

The Ursu.560801 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.560801 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Network activity contains more than one unique useragent.

Related domains:

www.wushi.pw
yun.wushi.hk

How to determine Ursu.560801?


File Info:

crc32: 772E7AAB
md5: c99520706c287154faaf6e968d893296
name: xpjzs.exe
sha1: dcdd9682e74c32c0870c9c471c9e1932eb4290f4
sha256: a95ce91aefb5eed369abe1c1658c9ebec51bac2a4bcf0ccdcd83a00099f87557
sha512: 5d597eaa8a1a9edfffc49d98174c75dd9cb5b0c3df9c3cf41ee7018d4ada0bfe2f935ea1df32d5a6755c2fcfb8258c3829f16748f2d804a4b90064a1212b42af
ssdeep: 49152:nLl+xig83QaxwXeXLoP0AY+EKheyxAgT5sb51epDfdqaVxbTUUQKD3zSZi3ECjk:Lsxi33sL0AXhhbxLTQDefRUKTzSA3Bg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x4f5cx8005x7248x6743x6240x6709 x8bf7x5c0ax91cdx5e76x4f7fx7528x6b63x7248
FileVersion: 1.0.0.0
Comments: x672cx7a0bx5e8fx4f7fx7528x6613x8bedx8a00x7f16x5199(http://www.eyuyan.com)
ProductName: x6613x8bedx8a00x7a0bx5e8f
ProductVersion: 1.0.0.0
FileDescription: x6613x8bedx8a00x7a0bx5e8f
Translation: 0x0804 0x04b0

Ursu.560801 also known as:

BkavHW32.Packed.
MicroWorld-eScanGen:Variant.Ursu.560801
FireEyeGeneric.mg.c99520706c287154
Qihoo-360Generic/Trojan.f17
ALYacGen:Variant.Ursu.560801
CylanceUnsafe
K7AntiVirusTrojan ( 004571581 )
BitDefenderGen:Variant.Ursu.560801
K7GWTrojan ( 004571581 )
Cybereasonmalicious.2e74c3
TrendMicroTROJ_GEN.R002C0RCS20
BitDefenderThetaGen:NN.ZexaF.34104.lB0@a4@0BUdb
APEXMalicious
AvastWin32:Trojan-gen
GDataWin32.Application.PUPStudio.A
AlibabaPacked:Win32/VMProtect.d39ae900
NANO-AntivirusTrojan.Win32.Black.hgywxl
AegisLabTrojan.Win32.Ursu.4!c
TencentWin32.Trojan.Suspicious.Taev
Ad-AwareGen:Variant.Ursu.560801
SophosMal/VMProtBad-A
ComodoVirus.Win32.Virut.CE@1fhkga
F-SecureTrojan.TR/Black.Gen2
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Ursu.560801 (B)
IkarusTrojan-Downloader.Win32.FakeIE
AviraTR/Black.Gen2
MAXmalware (ai score=80)
Antiy-AVLTrojan[Packed]/Win32.Vemply
Endgamemalicious (high confidence)
ArcabitTrojan.Ursu.D88EA1
SUPERAntiSpywareTrojan.Agent/Gen-OnlineGames
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
McAfeeArtemis!C99520706C28
MalwarebytesSpyware.OnlineGames
ESET-NOD32a variant of Win32/Packed.VMProtect.ABO
TrendMicro-HouseCallTROJ_GEN.R002C0RCS20
RisingMalware.Heuristic!ET#96% (RDMK:cmRtazrIfDtEjg3kNXHnAl8a88gU)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_100%
FortinetRiskware/VMProtBad
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Ursu.560801?

Ursu.560801 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment