Malware

Ursu.797776 malicious file

Malware Removal

The Ursu.797776 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.797776 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Attempts to remove evidence of file being downloaded from the Internet
  • Anomalous binary characteristics

How to determine Ursu.797776?


File Info:

crc32: 17AB177F
md5: 42dbcf8c9dc085cafd3454f3d165569b
name: 123.exe
sha1: 751d695a9e522dce172689f2df036bf5e597c75c
sha256: 520af6c1897272c88ab4d9e3ed5f1452d0340a3c35956756993cfe3492f6608b
sha512: 42fb4485059e3ca80d6e1b7736bc4b454947fa8a2f462b4e64f9ebc33ea391caf6dc17116c32164a39999822d874e7eb6776de5ffd93aaf1d817029554ba7c63
ssdeep: 12288:cLricj9cLOdl0KVAV/Ba5+yHSmZbJ2lkgwxX:cB0KWV/BaHS8a2
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ursu.797776 also known as:

MicroWorld-eScanGen:Variant.Ursu.797776
FireEyeGeneric.mg.42dbcf8c9dc085ca
ALYacGen:Variant.Ursu.797776
MalwarebytesBackdoor.AveMaria
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0056347d1 )
BitDefenderGen:Variant.Ursu.797776
K7GWTrojan ( 0056347d1 )
Cybereasonmalicious.c9dc08
TrendMicroTROJ_GEN.R03FC0PCS20
BitDefenderThetaGen:NN.ZexaF.34104.FuW@aq6MXwbi
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R03FC0PCS20
AvastWin32:Malware-gen
GDataGen:Variant.Ursu.797776
KasperskyTrojan-Spy.Win32.AveMaria.cyr
AlibabaTrojanSpy:Win32/AveMaria.a81b514a
ViRobotTrojan.Win32.Z.Ursu.514560
AegisLabTrojan.Win32.AveMaria.l!c
APEXMalicious
RisingTrojan.Generic@ML.90 (RDML:ANHUCrltBMSEXxUlb9KSSA)
Ad-AwareGen:Variant.Ursu.797776
SophosMal/Generic-S
F-SecureTrojan.TR/SPY.AveMaria.kvrxb
DrWebTrojan.PWS.Maria.3
ZillyaTrojan.AveMaria.Win32.452
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Ursu.797776 (B)
SentinelOneDFI – Malicious PE
CyrenW32/Trojan.ZWND-7408
AviraTR/SPY.AveMaria.kvrxb
Antiy-AVLTrojan[Spy]/Win32.AveMaria
Endgamemalicious (high confidence)
ArcabitTrojan.Ursu.DC2C50
ZoneAlarmTrojan-Spy.Win32.AveMaria.cyr
MicrosoftTrojan:Win32/Occamy.C
AhnLab-V3Malware/Win32.Generic.C4030283
McAfeeArtemis!42DBCF8C9DC0
MAXmalware (ai score=100)
VBA32TrojanSpy.AveMaria
PandaGeneric Malware
ESET-NOD32a variant of Win32/GenKryptik.EHCX
TencentWin32.Trojan-spy.Avemaria.Pdmp
YandexTrojan.Agent!+t/l7mFrFJw
IkarusTrojan.Win32.Krypt
eGambitUnsafe.AI_Score_99%
FortinetW32/AveMaria.CYR!tr
WebrootW32.Malware.Gen
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.Spy.92e

How to remove Ursu.797776?

Ursu.797776 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment