Malware

Ursu.767367 (file analysis)

Malware Removal

The Ursu.767367 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.767367 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Performs some HTTP requests

Related domains:

updateoss.xyhh.net

How to determine Ursu.767367?


File Info:

crc32: 6497E2A8
md5: 98133343d07f48af1a767691311b12c8
name: 98133343D07F48AF1A767691311B12C8.mlw
sha1: 853d04a97cdf4d677586c4ed03160b90eff8dee8
sha256: fae79c0780d73db42a4c59fb9c7147b421566b7e1d4b40a02199b071204d80ff
sha512: 36c29b227b8e9038707e0fd538e556beb935173726de1492c1f2ed2324ee6967fe9e8639ab4fd496ee07d2e2e2c9684886a361c57b4014f36330ff445e56ab12
ssdeep: 3072:Bkhw75le2pU+eu78xOEUuYn/U9xV8U9xV2VV2S:BIKle34zGTiVIS
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ursu.767367 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CylanceUnsafe
SangforRiskware.Win32.Agent.ky
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Ursu.767367
SymantecTrojan.Gen.MBT
APEXMalicious
KasperskyHEUR:Trojan-Downloader.Win32.Generic
AlibabaTrojanDownloader:Win32/Generic.ffe9226d
MicroWorld-eScanGen:Variant.Ursu.767367
TencentWin32.Trojan-downloader.Generic.Hryh
BitDefenderThetaAI:Packer.5C8C16931F
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.98133343d07f48af
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDownloader.Generic.bfjy
Antiy-AVLTrojan[Downloader]/Win32.AGeneric
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AAFA
AegisLabTrojan.Win32.Generic.a!c
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Ursu.767367
AhnLab-V3Malware/Win32.Generic.C4011005
McAfeeArtemis!98133343D07F
MAXmalware (ai score=83)
VBA32suspected of Trojan.Downloader.gen.h
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
RisingDownloader.Generic!8.141 (CLOUD)
MaxSecureTrojan.Malware.7175239.susgen
FortinetW32/Generic.X!tr.dldr
Paloaltogeneric.ml

How to remove Ursu.767367?

Ursu.767367 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment