Malware

How to remove “Ursu.810964”?

Malware Removal

The Ursu.810964 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.810964 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Ursu.810964?


File Info:

crc32: 2CD8D225
md5: 7d78c5a352a70876c1b998f3a61bc7ff
name: uzmod1.exe
sha1: 94d7d4c1eb32164cd3983035ce012f3b2fb8d711
sha256: 7ce7c50d8de685ceb9b5551d0568721b50d80ac18981714780f6ad141edc0325
sha512: 334a91669d9e0b1f5ea15a4e1302f862da3d33c657c1b2819d730eda52195954d4d68a51c7401b65862dc903d3b8c1b540343a0370f9914d16d99d7b13697340
ssdeep: 768:RmJwqtwoucE9ZCPIStPQ1CJpBW8p4FilbGVZ5dPZxAT1IP:Bq2ytISBWCPBJCilbGV1ATyP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: SCHNAUZERE
InternalName: Bakte
FileVersion: 1.00
CompanyName: Scotters
LegalTrademarks: Passivise3
Comments: Scotters
ProductName: LEVERING
ProductVersion: 1.00
FileDescription: teks
OriginalFilename: Bakte.exe

Ursu.810964 also known as:

DrWebTrojan.Siggen9.33818
MicroWorld-eScanGen:Variant.Ursu.810964
Qihoo-360Generic/Trojan.b6f
ALYacGen:Variant.Ursu.810964
CylanceUnsafe
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 005640021 )
BitDefenderGen:Variant.Ursu.810964
K7GWTrojan ( 005640021 )
TrendMicroTROJ_GEN.R002C0PD620
BitDefenderThetaGen:NN.ZevbaF.34106.gm0@aeR4ixni
F-ProtW32/VBKrypt.AHC.gen!Eldorado
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Packed.Noon-7650558-0
GDataGen:Variant.Ursu.810964
KasperskyTrojan-Spy.Win32.Noon.axmj
AlibabaTrojan:Win32/Injector.d2531fe8
TencentWin32.Trojan.Inject.Auto
Ad-AwareGen:Variant.Ursu.810964
SophosMal/FareitVB-W
F-SecureTrojan.TR/Injector.robwd
McAfee-GW-EditionFareit-FRR!7D78C5A352A7
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Ursu.810964 (B)
IkarusWin32.Outbreak
CyrenW32/VBKrypt.AHC.gen!Eldorado
AviraTR/Injector.robwd
Endgamemalicious (moderate confidence)
ArcabitTrojan.Ursu.DC5FD4
ZoneAlarmTrojan-Spy.Win32.Noon.axmj
MicrosoftTrojan:Win32/Guloader.GM!MTB
AhnLab-V3Trojan/Win32.VBKrypt.R329099
Acronissuspicious
VBA32BScope.Trojan.Wacatac
MAXmalware (ai score=84)
MalwarebytesTrojan.GuLoader.VB
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Injector.ELJJ
TrendMicro-HouseCallTROJ_GEN.R002C0PD620
RisingTrojan.Injector!8.C4 (CLOUD)
FortinetW32/GenKryptik.EWHQ!tr
AVGWin32:TrojanX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Ursu.810964?

Ursu.810964 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment