Malware

Ursu.713104 malicious file

Malware Removal

The Ursu.713104 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.713104 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Attempts to create or modify system certificates

Related domains:

kbangserver.kuwo.cn

How to determine Ursu.713104?


File Info:

crc32: 8EF83ABC
md5: d58ea363a088e93b82a9978bd4945a50
name: setup_2.0.exe
sha1: beb69e92e2604c6bf259da0bca220826728efb90
sha256: 5013d8b46e40714ef1a1b931378bbd322ecb67464d7d014346ab4493fa8199b4
sha512: 20035d854595279c36b59b6e6ac082d21e9feb1939b7f60f5fa88291495f8a130a3d6d5a14a3e5231fa8732d08a5f0a478374026f833496c0d9d8bd4ff235ae6
ssdeep: 49152:Ts0lEqaiPDHRYkhZVl4FgAUeqQ8P+Og6NQtxsQ:ACEXijRrfqpUfQ0b
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 52pojie By iPhone8Plus
FileVersion: 2.0.0.0
CompanyName: 52pojie By iPhone8Plus
Comments: 52pojie By iPhone8Plus
ProductName: 52pojie By iPhone8Plus
ProductVersion: 2.0.0.0
FileDescription: 52pojie By iPhone8Plus
Translation: 0x0804 0x04b0

Ursu.713104 also known as:

BkavHW32.Packed.
MicroWorld-eScanGen:Variant.Ursu.713104
FireEyeGeneric.mg.d58ea363a088e93b
CAT-QuickHealTrojan.Packed
McAfeeArtemis!D58EA363A088
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusUnwanted-Program ( 004eb1401 )
BitDefenderGen:Variant.Ursu.713104
K7GWUnwanted-Program ( 004eb1401 )
Cybereasonmalicious.2e2604
BitDefenderThetaGen:NN.ZexaF.34106.fE0@aq7btmcb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/FlyStudio.Packed.Q potentially unwanted
APEXMalicious
AvastWin32:Malware-gen
GDataGen:Variant.Ursu.713104
AegisLabRiskware.Win32.Malicious.1!c
TencentWin32.Trojan.Gen.Wrgo
Endgamemalicious (high confidence)
SophosGeneric PUA LO (PUA)
ComodoTrojWare.Win32.Agent.ISVQ@5mbonp
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.vc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Ursu.713104 (B)
CyrenW32/Trojan.GTOL-1457
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Occamy
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Ursu.DAE190
AhnLab-V3Malware/Win32.Generic.C3612238
Acronissuspicious
ALYacGen:Variant.Ursu.713104
VBA32BScope.Adware.Kqheb
MalwarebytesRiskWare.Packed.FlyStudio
RisingTrojan.Wacatac!8.10C01 (CLOUD)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
FortinetRiskware/FlyStudio_Packed
Ad-AwareGen:Variant.Ursu.713104
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.74747704.susgen

How to remove Ursu.713104?

Ursu.713104 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment