Malware

Ursu.696020 removal

Malware Removal

The Ursu.696020 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.696020 virus can do?

  • Executable code extraction
  • Reads data out of its own binary image
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.696020?


File Info:

crc32: 75D93497
md5: bfcef90a1cae653b9fb4675067fb24e3
name: YuWang_Setup_4.3.3.4.exe
sha1: 89fe4a63e4e3f020b8799c0108963850edf13d99
sha256: 8d042cb3559f2090a9f21b6f9160afaa95cd7e534ddc4be3a01adccec04a1a40
sha512: c648d81edd787bdc620fe62842c1a5d82433d193db62e9b5a32c53adc8078b6b7a88bf94c4210a9e1c8fd45358bb8e9b05560991e47adf64fc4a4e1ab0e0da44
ssdeep: 98304:BR05ZHiTlZ3Z+144yNscc/DspQQ+HHg8SzEnJDNPF:z05ZK3ga4zccb7fSAJJF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2014
InternalName: Setup
FileVersion: 3.9.0.0
ProductName: x4e91x76d8x5b89x88c5x7a0bx5e8f
ProductVersion: 3.9.0.0
FileDescription: x4e91x76d8x5b89x88c5x7a0bx5e8f
OriginalFilename: Setup.exe
Translation: 0x0804 0x04b0

Ursu.696020 also known as:

BkavW32.AIDetectVM.malware
DrWebTrojan.PWS.Siggen2.9368
MicroWorld-eScanGen:Variant.Ursu.696020
McAfeeArtemis!BFCEF90A1CAE
CylanceUnsafe
AegisLabTrojan.Win32.Ursu.4!c
BitDefenderGen:Variant.Ursu.696020
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_80% (W)
BitDefenderThetaGen:NN.ZexaF.34106.@F3bau!pXYej
APEXMalicious
Paloaltogeneric.ml
GDataGen:Variant.Ursu.696020
ViRobotTrojan.Win32.Z.Ursu.4274199
SophosMal/Behav-024
F-SecureTrojan.TR/Crypt.ASPM.Gen
ZillyaTrojan.GenericKD.Win32.243965
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.rc
FireEyeGeneric.mg.bfcef90a1cae653b
EmsisoftGen:Variant.Ursu.696020 (B)
IkarusTrojan.PSW.Agent
AviraTR/Crypt.ASPM.Gen
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
ArcabitTrojan.Ursu.DA9ED4
MicrosoftTrojan:Win32/Occamy.C
VBA32BScope.Trojan.Agent
MAXmalware (ai score=85)
RisingTrojan.Occamy!8.F1CD (RDMK:cmRtazqvj9H0cDD8o8wdLDCTKvy9)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_97%
AVGWin32:Malware-gen
Cybereasonmalicious.a1cae6
AvastWin32:Malware-gen
MaxSecureTrojan.Malware.83820589.susgen

How to remove Ursu.696020?

Ursu.696020 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment