Malware

Ursu.768565 removal

Malware Removal

The Ursu.768565 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.768565 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system

How to determine Ursu.768565?


File Info:

crc32: D60701E9
md5: 3e33d9eeb3244d57dfb1a8beb0ac1971
name: Scanned-BL.exe
sha1: 6ee05e4d31769472799b56036c30d35168a52414
sha256: ea77741f496225f09994ce297f0e0c0064e9b589ef738ebefb4c2ccb0053255f
sha512: d7be169753a58cf948e98c678cad305fc30c70e01b78b989de0a44a8ef10580f7c95b87d5b9a9b41ef7718c9ba0ec1161927bcebce7f3bde7ac1a4df69750f70
ssdeep: 6144:URdM0Gl8w4Y/YYnu6Gy2hvzobuA/5KnyqM+ZFVhkiT:Ug0GlHSyMrotwyqhVhkiT
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2016
Assembly Version: 1.0.0.0
InternalName: sTlAu.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: SoftRenderer
ProductVersion: 1.0.0.0
FileDescription: SoftRenderer
OriginalFilename: sTlAu.exe

Ursu.768565 also known as:

MicroWorld-eScanGen:Variant.Ursu.768565
FireEyeGeneric.mg.3e33d9eeb3244d57
McAfeeArtemis!3E33D9EEB324
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderGen:Variant.Ursu.768565
F-ProtW32/MSIL_Kryptik.APZ.gen!Eldorado
APEXMalicious
GDataGen:Variant.Ursu.768565
KasperskyHEUR:Trojan.MSIL.RRAT.gen
AlibabaTrojan:MSIL/GenKryptik.3b564252
TencentMsil.Trojan.Rrat.Llhj
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Ursu.768565 (B)
F-SecureHeuristic.HEUR/AGEN.1133748
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminesuspicious.low.ml.score
CyrenW32/MSIL_Kryptik.APZ.gen!Eldorado
AviraHEUR/AGEN.1133748
WebrootW32.Trojan.Gen
MAXmalware (ai score=83)
ArcabitTrojan.Ursu.DBBA35
ZoneAlarmHEUR:Trojan.MSIL.RRAT.gen
MicrosoftTrojan:Win32/Wacatac.C!ml
VBA32CIL.HeapOverride.Heur
ALYacGen:Variant.Ursu.768565
Ad-AwareGen:Variant.Ursu.768565
MalwarebytesTrojan.Crypt.MSIL.Generic
ESET-NOD32a variant of MSIL/Kryptik.VQY
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Kryptik.VQY!tr
BitDefenderThetaGen:NN.ZemsilF.34108.qm0@aihToel

How to remove Ursu.768565?

Ursu.768565 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment