Malware

Should I remove “Ursu.706163”?

Malware Removal

The Ursu.706163 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.706163 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
vampiri-online.ru
a.tomx.xyz

How to determine Ursu.706163?


File Info:

crc32: 9B5BC78B
md5: e93cd5c067f444c752b10e752bb73cb1
name: E93CD5C067F444C752B10E752BB73CB1.mlw
sha1: c89da258b344a262a2da8098f01bdcaa78a69f5c
sha256: 2f5fd92119e75c1abea1ae9effdf89d3a58567f21562e0cb0cdf19ba008e73a9
sha512: 7c0105e0926715e5dbc8babb1b4d85fadc0b8e2c322068913e2bfb41caa9e5970e36730eb3022c13c6eeed2568d90d3aeeb1ae86696f9247502ce10f2c507aa8
ssdeep: 6144:n/oZikttGIquMughLq7xiWW1Z4o1flPr4kGIkPJeT9Wusq85BFff5J6RAQOVV:o+oXo1NT4RWinVV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ursu.706163 also known as:

LionicTrojan.Win32.Blocker.j!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader7.33981
CynetMalicious (score: 99)
ALYacGen:Variant.Ursu.706163
CylanceUnsafe
AlibabaRansom:Win32/Blocker.58bb9c46
Cybereasonmalicious.067f44
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.bgrl
BitDefenderGen:Variant.Ursu.706163
NANO-AntivirusTrojan.Win32.Dapato.cxhtre
MicroWorld-eScanGen:Variant.Ursu.706163
TencentWin32.Trojan.Blocker.Ajvg
Ad-AwareGen:Variant.Ursu.706163
ComodoMalware@#38r9khg9arf1i
BitDefenderThetaGen:NN.ZedlaF.34170.rC4@aSgq5opc
VIPRETrojan.Win32.Generic!BT
TrendMicroPossible_SMHPQAKBOTTHA
McAfee-GW-EditionBehavesLike.Win32.Dropper.fh
FireEyeGen:Variant.Ursu.706163
EmsisoftGen:Variant.Ursu.706163 (B)
SentinelOneStatic AI – Suspicious PE
WebrootW32.Malware.Heur.Dkvt
AviraTR/Dldr.Delphi.Gen
Antiy-AVLTrojan/Generic.ASMalwS.279D9E
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Ursu.706163
TACHYONRansom/W32.Blocker.375296
McAfeeArtemis!E93CD5C067F4
MAXmalware (ai score=99)
PandaTrj/CI.A
TrendMicro-HouseCallPossible_SMHPQAKBOTTHA
YandexTrojan.Blocker!B9WPIqpoS40
IkarusTrojan-Ransom.Blocker
FortinetW32/Agent.DRO!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ursu.706163?

Ursu.706163 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment