Malware

What is “Ursu.81006”?

Malware Removal

The Ursu.81006 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.81006 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.81006?


File Info:

crc32: 3C4908B8
md5: 18d80660346fe08ae8f34755511e1fd9
name: 18D80660346FE08AE8F34755511E1FD9.mlw
sha1: 01ce2fcdd26e4e2535323b2bcbd46e4512674a2e
sha256: 6f442766f6b3cde369f612aab712d75e542f9e535c02b22607d7811ddec161ee
sha512: a8c73af0e17082d41dd1a1f454ddfb5c02464ed19344519c9dc695f2c4d2bc8a7c56dfa2e9d02104a33997b4d794dd2f22d15930abac0042d5914857f0684119
ssdeep: 6144:T9atGHq/apitQ2o+NVM/osyxTejqrMNFmZnI+rZHgJdASpT9G64HyMfkIAhZL+D:hpVo4QsyVej/+VA7s64HyvIk+D7
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: avast
Assembly Version: 543.34.456.564
InternalName: avast.exe
FileVersion: 543.34.456.564
CompanyName: avast
LegalTrademarks: avast
Comments: avast
ProductName: avast
ProductVersion: 543.34.456.564
FileDescription: avast
OriginalFilename: avast.exe

Ursu.81006 also known as:

K7AntiVirusTrojan ( 700000121 )
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
ALYacGen:Variant.Ursu.81006
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 700000121 )
Cybereasonmalicious.0346fe
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.SGT
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.MSIL.Crypt.gen
BitDefenderGen:Variant.Ursu.81006
NANO-AntivirusTrojan.Win32.Chgt.dcvrfz
ViRobotTrojan.Win32.Z.Reputation.465920
MicroWorld-eScanGen:Variant.Ursu.81006
TencentWin32.Trojan.Generic.Eaxs
Ad-AwareGen:Variant.Ursu.81006
SophosML/PE-A
ComodoMalware@#6vpxzepogw4v
BitDefenderThetaGen:NN.ZemsilF.34294.Cq0@aKOpgGi
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R007C0PKF21
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.18d80660346fe08a
EmsisoftGen:Variant.Ursu.81006 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1125952
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.AF5D2B
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:MSIL/Bladabindi
GDataGen:Variant.Ursu.81006
AhnLab-V3Trojan/Win.Generic.C4766071
McAfeeRDN/Generic.grp
MAXmalware (ai score=83)
PandaTrj/Chgt.A
TrendMicro-HouseCallTROJ_GEN.R007C0PKF21
YandexTrojan.Agent!9Sc68qlcN9A
IkarusTrojan.MSIL.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.IILKBKJ!tr
AVGWin32:Malware-gen

How to remove Ursu.81006?

Ursu.81006 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment