Malware

Ursu.799245 (B) information

Malware Removal

The Ursu.799245 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.799245 (B) virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

Related domains:

z.whorecord.xyz
a.tomx.xyz
api.ncii.cn

How to determine Ursu.799245 (B)?


File Info:

crc32: 0199AA2F
md5: 4012a2f3409c3d9bcf4a7ab0691cb050
name: 4012A2F3409C3D9BCF4A7AB0691CB050.mlw
sha1: 93c90bbadeb738b475293da1958f44a68ed4d50c
sha256: 2efbb7ddb8368c8ca771db583fcc00e8eb74ea6b5ee3c30bbba691e90693b13a
sha512: 2149a3ce30087ec2e151dc36a0b80ec3d53dcfe83848053bd461a700244fe890ad5f101c8ee12a48ad7156fc753d9f4e1610c5b33c0756975113b2b23c77a9fa
ssdeep: 12288:j2qkiBP2nC7PAxIRyI8uH5BnCxGkawNI60Z/w3OCtlz6Y+oS:j2qkECYPAxK8M5BnEau0ae6lzV
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: fanyi.julym.com
FileVersion: 2.5.0.0
CompanyName: Macro
Comments: Macro Tools
ProductName: Macro Tools
ProductVersion: 2.5.0.0
FileDescription: Macro Tools
Translation: 0x0804 0x04b0

Ursu.799245 (B) also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.799245
FireEyeGeneric.mg.4012a2f3409c3d9b
McAfeeGenericRXAA-AA!4012A2F3409C
CylanceUnsafe
K7AntiVirusTrojan ( 005246d51 )
BitDefenderGen:Variant.Ursu.799245
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.3409c3
SymantecML.Attribute.HighConfidence
APEXMalicious
ClamAVWin.Malware.Zusy-6717397-0
RisingTrojan.ELang!1.64ED (CLOUD)
Ad-AwareGen:Variant.Ursu.799245
EmsisoftGen:Variant.Ursu.799245 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.bc
SophosGeneric PUA JD (PUA)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
MAXmalware (ai score=89)
Antiy-AVLGrayWare/Win32.FlyStudio.a
KingsoftWin32.Heur.KVM099.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.D2!ml
ArcabitTrojan.Ursu.DC320D
GDataWin32.Application.FlyStudio.F
CynetMalicious (score: 100)
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34804.UmKfaeWgtweb
ALYacGen:Variant.Ursu.799245
VBA32BScope.TrojanPSW.QQPass
MalwarebytesTrojan.MalPack.FlyStudio
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
eGambitHackTool.Generic
Qihoo-360Generic/Trojan.f5e

How to remove Ursu.799245 (B)?

Ursu.799245 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment