Malware

Ursu.703600 information

Malware Removal

The Ursu.703600 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.703600 virus can do?

  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)

Related domains:

api.xp666.com
download.xp666.com

How to determine Ursu.703600?


File Info:

crc32: C3AD286D
md5: 8b7963d7e25a578850366f3f4d8d769b
name: wmwb86982345_904.exe
sha1: 263091d6a0a0c830821acdc0d6759576633127e0
sha256: 16925deec5680ef6b12b86ef3ac7d879a95d13324bcc7817714d071f3a73c3d2
sha512: 4fec112eb3faa19d3f14971f840cc5a8fb48ae49e572611cb9db83a3134d177cb721c253d63641e6a305bbac88d5727354e01ecc22a2b64a50785524c56af626
ssdeep: 49152:X4WrlWTSMKiFjStOMsz2EZ1bdzoi4lH/tTC2TGH0Zdw:XZr+2EzbdzofCqZd
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyrightxff08Cxff092019
FileVersion: 3.9.0.309
ProductName: x8f6fx4ef6x4e0bx8f7dx5668
ProductVersion: 3.9.0.210
FileDescription: x8f6fx4ef6x4e0bx8f7dx5668
OriginalFilename: FastDownload.exe
Translation: 0x0804 0x03a8

Ursu.703600 also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanGen:Variant.Ursu.703600
BitDefenderGen:Variant.Ursu.703600
Cybereasonmalicious.7e25a5
BitDefenderThetaAI:Packer.C8AD9A6419
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
GDataGen:Variant.Ursu.703600
KasperskyHEUR:Trojan-Downloader.Win32.Agent.gen
Ad-AwareGen:Variant.Ursu.703600
EmsisoftGen:Variant.Ursu.703600 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.wh
FireEyeGeneric.mg.8b7963d7e25a5788
SentinelOneDFI – Malicious PE
JiangminTrojan.Agentb.glb
Endgamemalicious (high confidence)
ArcabitTrojan.Ursu.DABC70
ZoneAlarmHEUR:Trojan-Downloader.Win32.Agent.gen
MicrosoftTrojan:Win32/Wacatac.C!ml
AhnLab-V3Malware/Gen.Generic.C2889838
VBA32TScope.Trojan.Delf
ALYacGen:Variant.Ursu.703600
MAXmalware (ai score=84)
MalwarebytesTrojan.Downloader.Aspack
ESET-NOD32a variant of Win32/Duote.A
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazqsGOlSlAlvOO+irti682+3)
IkarusTrojan.Win32.Duote
AVGWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.fc8

How to remove Ursu.703600?

Ursu.703600 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment