Malware

Ursu.824275 (B) removal

Malware Removal

The Ursu.824275 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.824275 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.824275 (B)?


File Info:

crc32: E7F4DC0F
md5: 1db772f0c794f854adb5c78889113226
name: 20413687ead846bae3d6dc2187ebf1d00be.exe
sha1: f4cec0fb8520461d8fade28d0df404311b14a648
sha256: 7afc7aad415a6cc1bf4b429256b44b3da8de8973739892aef3bd4b7b991c9d9e
sha512: 846c7493283a80e93edbca70d03b53faf286c8046e094ede6c1ff2b41f3236d009f8b0792ab8fe15144b5c77b0662c33af35b771b98079316b8faa08e294ac00
ssdeep: 12288:QboBb/W9ANGBAFb5i0P6HfewKQLYg0yCx:4xBAiAHwfz
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) Microsoft Corp. 1981-1997
InternalName: Timer.exe
FileVersion: 5.00.1636.1
CompanyName: Microsoft Corporation
ProductName: Microsoft(R) Windows NT(R) Operating System
ProductVersion: 5.00.1636.1
FileDescription: Microsoftxae Timer
OriginalFilename: Timer.exe
Translation: 0x0409 0x04b0

Ursu.824275 (B) also known as:

Qihoo-360QVM41.1.Malware.Gen
CylanceUnsafe
BitDefenderGen:Variant.Ursu.824275
BitDefenderThetaGen:NN.ZexaF.34106.Cy1@aiLwzBeO
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.CXRGIDW
APEXMalicious
GDataGen:Variant.Ursu.824275
Ad-AwareGen:Variant.Ursu.824275
F-SecureTrojan.TR/AD.TrickBot.byhyn
DrWebTrojan.Trick.46562
Invinceaheuristic
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.1db772f0c794f854
EmsisoftGen:Variant.Ursu.824275 (B)
SentinelOneDFI – Suspicious PE
WebrootW32.Trojan.Gen
AviraTR/AD.TrickBot.byhyn
Endgamemalicious (high confidence)
Acronissuspicious
MAXmalware (ai score=87)
eGambitUnsafe.AI_Score_98%
FortinetW32/GenKryptik.EIRG!tr

How to remove Ursu.824275 (B)?

Ursu.824275 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment