Malware

Ursu.771158 removal guide

Malware Removal

The Ursu.771158 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.771158 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

How to determine Ursu.771158?


File Info:

crc32: F82B2C3A
md5: 76b32bd38d1aa8a113f19e6d65adcd8d
name: wxbin.exe
sha1: bd68a7026b9737d482bf1ba61c9def40317e19f5
sha256: e9b56f8698da02e41f42ceda4d9ee474c1e8472e58f1a27d98527e7399116ef1
sha512: c5fb5181091d7e2fdb7c39988559f388892c204b6cac0101e0fd95938395cfc00f63bc7083e5e2b249967cdf1125c577e90dd515466879f7bddc8921aea7c8f3
ssdeep: 12288:0UhQwqQSLce4SOrOSAq8tVs7W8rV/r/p:x5e4trm8rVz/p
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ursu.771158 also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Ursu.771158
FireEyeGeneric.mg.76b32bd38d1aa8a1
Qihoo-360Generic/Trojan.231
McAfeeRDN/Generic PWS.y
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005612fb1 )
BitDefenderGen:Variant.Ursu.771158
K7GWTrojan ( 005612fb1 )
Cybereasonmalicious.38d1aa
TrendMicroTROJ_GEN.R011C0PBQ20
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataGen:Variant.Ursu.771158
KasperskyTrojan-Spy.Win32.AveMaria.cwo
AlibabaTrojanSpy:Win32/AveMaria.877e5b75
ViRobotTrojan.Win32.Z.Agent.419328.MMW
AegisLabTrojan.Multi.Generic.4!c
AvastWin32:Trojan-gen
TencentWin32.Trojan.Heur.Ajbv
Ad-AwareGen:Variant.Ursu.771158
SophosMal/Generic-S
F-SecureTrojan.TR/AD.MortyStealer.ejnsn
Invinceaheuristic
McAfee-GW-EditionRDN/Generic PWS.y
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Ursu.771158 (B)
IkarusTrojan.Win32.Krypt
CyrenW32/Trojan.XRAM-8709
AviraTR/AD.MortyStealer.ejnsn
MAXmalware (ai score=99)
Antiy-AVLTrojan/Win32.Wacatac
Endgamemalicious (high confidence)
ArcabitTrojan.Ursu.DBC456
ZoneAlarmTrojan-Spy.Win32.AveMaria.cwo
MicrosoftTrojanSpy:Win32/AveMaria.BM
Acronissuspicious
ALYacGen:Variant.Ursu.771158
ESET-NOD32a variant of Win32/Kryptik.HBLC
TrendMicro-HouseCallTROJ_GEN.R011C0PBQ20
RisingSpyware.AveMaria!8.108C2 (RDMK:cmRtazo1kuo+H0Gih3TZdapNPBE1)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_85%
FortinetPossibleThreat.MU
BitDefenderThetaAI:Packer.8B2B795D1F
AVGWin32:Trojan-gen
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.74932962.susgen

How to remove Ursu.771158?

Ursu.771158 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment