Malware

Ursu.805679 removal instruction

Malware Removal

The Ursu.805679 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.805679 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Detects Sandboxie through the presence of a library
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Creates a copy of itself

Related domains:

nibiru3.duckdns.org
nibiru4.duckdns.org
nibiru5.duckdns.org
karmina113.sytes.net
karmina117.sytes.net
karmina118.sytes.net
karmina119.sytes.net

How to determine Ursu.805679?


File Info:

crc32: C19EFE2A
md5: efc1c7421308412e789de36f40a5ff55
name: EFC1C7421308412E789DE36F40A5FF55.mlw
sha1: 654472f39e21c66bd8230431155e154789cac611
sha256: 64ecc5d104954f024c442068a4a31e0e721b8f3fd947bf0845328cbc65db3d9b
sha512: 1928f525653eca0685df254c8ed94530bfb774a1024a396d4ea98e7a9e76cca830b3aa1458cd1635ffd6b48d8ab9fd453341822231989da50523dedb486f55c1
ssdeep: 3072:EgWxP3t4P/dHHdS6kRR7ykHL5STdxonPo9fjKt2U2Jjv:Eg2+V9S6gdyLdSL2U2
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Audio Realtek Control Copyright xa9 2017
Assembly Version: 1.145.1.178
InternalName: WSReset.exe
FileVersion: 1.145.1.178
CompanyName: Realtek Corporation
Comments: Audio Realtek Control
ProductName: Audio Realtek Control
ProductVersion: 1.145.1.178
FileDescription: Audio Realtek Control
OriginalFilename: WSReset.exe

Ursu.805679 also known as:

LionicTrojan.MSIL.Blocker.j!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.805679
ALYacGen:Variant.Ursu.805679
CylanceUnsafe
SangforSuspicious.Win32.Save.a
AlibabaRansom:MSIL/Blocker.ddda1848
K7GWTrojan ( 0055f7d71 )
K7AntiVirusTrojan ( 0055f7d71 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.CMU
APEXMalicious
AvastWin32:RATX-gen [Trj]
CynetMalicious (score: 99)
KasperskyHEUR:Trojan-Ransom.MSIL.Blocker.gen
BitDefenderGen:Variant.Ursu.805679
NANO-AntivirusTrojan.Win32.Ransom.hgneja
TencentMsil.Trojan.Blocker.Apmn
Ad-AwareGen:Variant.Ursu.805679
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34142.wm0@amLXGCji
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.efc1c7421308412e
EmsisoftGen:Variant.Ursu.805679 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.MSIL.okfs
AviraHEUR/AGEN.1100374
eGambitUnsafe.AI_Score_99%
ZoneAlarmHEUR:Trojan-Ransom.MSIL.Blocker.gen
GDataGen:Variant.Ursu.805679
AhnLab-V3Trojan/Win32.RL_FCN.C4022782
McAfeeArtemis!EFC1C7421308
MAXmalware (ai score=84)
PandaTrj/GdSda.A
YandexTrojan.Agent!mBvDcfQfWwo
IkarusTrojan.MSIL.Agent
FortinetMSIL/Blocker.CMU!tr
AVGWin32:RATX-gen [Trj]
Paloaltogeneric.ml

How to remove Ursu.805679?

Ursu.805679 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment