Malware

Ursu.782666 information

Malware Removal

The Ursu.782666 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.782666 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • Checks for the presence of known windows from debuggers and forensic tools
  • The following process appear to have been packed with Themida: 1.exe
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
2no.co
a.tomx.xyz

How to determine Ursu.782666?


File Info:

crc32: 846A3A16
md5: 68fde744cb9d56dac46c6743a3f5a6f3
name: 1.exe
sha1: 1e84f945c1416bf0d9eef8a0954a48523fd1c385
sha256: 94b0a6b6e01a61982ec4b42899c119ac0c7ca3b753380f7573b25b990a4aabb3
sha512: fc50f136da4d2f7d39de48289fb20373f6c7bf1afc104b53b82ec8b2f0ef990453b432e48ad3b44586c273b85fa5ec59e34990711322075b06e2adf6fcd485ff
ssdeep: 49152:cFSMAnMEutuDOaY4u/yqu9e2qXRsCCgxbK4H6rnD:WAnMhiE4uaxU7CobTH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.1.28.01
ProductName:
ProductVersion: 1.1.28.01
FileDescription:
OriginalFilename:
Translation: 0x0409 0x04b0

Ursu.782666 also known as:

BkavW32.HfsAutoB.
MicroWorld-eScanGen:Variant.Ursu.782666
FireEyeGeneric.mg.68fde744cb9d56da
Qihoo-360HEUR/QVM19.1.C67B.Malware.Gen
CylanceUnsafe
SangforMalware
BitDefenderGen:Variant.Ursu.782666
Cybereasonmalicious.5c1416
BitDefenderThetaGen:NN.ZexaF.34098.aA0aa0HDQ8ji
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Themida.CJV
APEXMalicious
GDataGen:Variant.Ursu.782666
KasperskyTrojan.Win32.Phpw.ajba
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazqmKDceQwFcSuIWdUCI3EAb)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Ursu.782666 (B)
F-SecureHeuristic.HEUR/AGEN.1045050
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.PWSBanker.vc
Trapminemalicious.high.ml.score
IkarusTrojan-Downloader.Win32.Autohk
AviraHEUR/AGEN.1045050
MAXmalware (ai score=86)
MicrosoftTrojan:Win32/Wacatac.D!ml
ArcabitTrojan.Ursu.DBF14A
ZoneAlarmTrojan.Win32.Phpw.ajba
Acronissuspicious
Ad-AwareGen:Variant.Ursu.782666
MalwarebytesTrojan.Downloader.AHK.Themida
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_96%
CrowdStrikewin/malicious_confidence_80% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Ursu.782666?

Ursu.782666 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment