Malware

What is “Ursu.640054 (B)”?

Malware Removal

The Ursu.640054 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.640054 (B) virus can do?

  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Queries information on disks, possibly for anti-virtualization
  • Steals private information from local Internet browsers

Related domains:

z.whorecord.xyz
mediav.shzhanmeng.com
a.tomx.xyz

How to determine Ursu.640054 (B)?


File Info:

crc32: D20CFE59
md5: 49c380a8351f58f3a4624c82d7fc7b62
name: urlreport-5.exe
sha1: 7da49845598c6cd81919e5160bf7dcaf9d0706f1
sha256: 7ce3ae81a176f1319b73e09bfe6008c4260619850d02d530e97e2611407d1471
sha512: e938b72028c922dc61b52da7998c4e6e1a2871e6f65ebdb664617e6ca35e34fdcfc89725054595a6c7fc7e27d56c18ae8e23f2b655d0fc6b80be177ed8a1f6b5
ssdeep: 49152:tHsHhhDb3O4NA+o3D6l+ZDQLnnL96/TBfb3V1bRIZsVJI:Zs/Dbe4A3Dk+ZDQLn56pV1b8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2019
InternalName: UrlRepor.exe
FileVersion: 1.0.1.9
ProductName: x8bb0x5f55
ProductVersion: 1.0.1.9
FileDescription: x8bb0x5f55
Translation: 0x0804 0x04b0

Ursu.640054 (B) also known as:

MicroWorld-eScanGen:Variant.Ulise.85501
FireEyeGen:Variant.Ulise.85501
McAfeeGenericRXIX-RO!49C380A8351F
VIPRETrojan.Win32.Generic!BT
K7AntiVirusAdware ( 00511e4b1 )
BitDefenderGen:Variant.Ulise.85501
K7GWAdware ( 00511e4b1 )
BitDefenderThetaGen:NN.ZexaCO3.32245.5D2@aeHd7Xcj
SymantecML.Attribute.HighConfidence
GDataGen:Variant.Ulise.85501
RisingTrojan.Generic@ML.82 (RDML:SjFuFkJzZzPLkeSniZO2gQ)
Ad-AwareGen:Variant.Ulise.85501
TrendMicroTROJ_GEN.R020C0PK719
McAfee-GW-EditionGenericRXIX-RO!49C380A8351F
EmsisoftGen:Variant.Ursu.640054 (B)
ArcabitTrojan.Ulise.D14DFD
MicrosoftPUA:Win32/KuaiZip
VBA32BScope.Adware.KuaiZip
ALYacGen:Variant.Ulise.85501
MAXmalware (ai score=86)
MalwarebytesAdware.ChinAd
PandaTrj/CI.A
ESET-NOD32a variant of Win32/KuaiZip.N potentially unwanted
TrendMicro-HouseCallTROJ_GEN.R020C0PK719
YandexRiskware.Agent!
FortinetW32/Ursu.75686!tr
AVGWin32:UnwantedSig [PUP]
AvastWin32:UnwantedSig [PUP]

How to remove Ursu.640054 (B)?

Ursu.640054 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment