Malware

Ursu.754316 (B) malicious file

Malware Removal

The Ursu.754316 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.754316 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Attempts to remove evidence of file being downloaded from the Internet
  • A process attempted to delay the analysis task by a long amount of time.

Related domains:

bbus86.ddns.net

How to determine Ursu.754316 (B)?


File Info:

crc32: 4870072E
md5: b53a201ca842cfd5ab892f5251f8f52d
name: 112.exe
sha1: 0e0be369948ba5e0752532a2ce9d61732ca384ab
sha256: 6cd586e5948f05a89a529d86559316aaa979fd119485aa54f4a80568183c044d
sha512: 2323613c56df548e7e64e89dd1fefbcc5e4d0a5753abc53463dea3bf0b7435999812719ee4f866eae7723dac59783ca4be22af40ae6f9d2c1cd040a54cede12b
ssdeep: 6144:YWsnSho0LBNp1xEQf0XyG9pG0VduAAOuZYjmQ6GdwPgViSr:tkioGp1x3KDKAUCyQnetS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (c) 2000-2019 Martin Prikryl
CompanyName: Martin Prikryl
FileDescription: WinSCP: SFTP, FTP, WebDAV, S3 and SCP client
ProductVersion: 5.15.2.0
ProductName: WinSCP
Translation: 0x0409 0x0514

Ursu.754316 (B) also known as:

MicroWorld-eScanGen:Variant.Ursu.754316
FireEyeGeneric.mg.b53a201ca842cfd5
CAT-QuickHealTrojan.Ursu
McAfeeArtemis!B53A201CA842
ALYacGen:Variant.Ursu.754316
CrowdStrikewin/malicious_confidence_60% (W)
BitDefenderGen:Variant.Ursu.754316
K7GWTrojan ( 004f31091 )
K7AntiVirusTrojan ( 004f31091 )
TrendMicroTROJ_GEN.R002C0WBE20
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
GDataGen:Variant.Ursu.754316
KasperskyTrojan.Win32.Zonidel.ezi
AlibabaTrojan:Win32/Zonidel.5d234d10
NANO-AntivirusTrojan.Win32.Maria.hagmtx
AegisLabTrojan.Win32.Ursu.4!c
RisingSpyware.AveMaria!8.108C2 (CLOUD)
Endgamemalicious (high confidence)
SophosMal/Generic-S
F-SecureTrojan.TR/AD.MortyStealer.wfhbz
DrWebTrojan.PWS.Maria.3
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.CoinMiner.gh
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Ursu.754316 (B)
IkarusTrojan.Win32.Agent
CyrenW32/Trojan.IYRN-2550
JiangminTrojanSpy.AveMaria.hq
WebrootW32.Malware.Gen
AviraTR/AD.MortyStealer.wfhbz
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan[Spy]/Win32.AveMaria
ArcabitTrojan.Ursu.DB828C
ZoneAlarmTrojan.Win32.Zonidel.ezi
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
VBA32TrojanSpy.AveMaria
Ad-AwareGen:Variant.Ursu.754316
MalwarebytesBackdoor.AveMaria
PandaTrj/GdSda.A
ESET-NOD32Win32/Agent.TJS
TrendMicro-HouseCallTROJ_GEN.R002C0WBE20
SentinelOneDFI – Suspicious PE
MaxSecureTrojan.Malware.74832022.susgen
FortinetW32/Agent.TJS!tr
BitDefenderThetaGen:NN.ZexaF.34090.Bu0@aCXS3tji
AVGWin32:Trojan-gen
Cybereasonmalicious.ca842c
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.8ce

How to remove Ursu.754316 (B)?

Ursu.754316 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment