Categories: Malware

How to remove “Ursu.847078”?

The Ursu.847078 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.847078 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Ursu.847078?


File Info:

crc32: B1A6F327md5: f857575c9cd5c2bb3a0b8f30f4b3ad59name: game.exesha1: cb012591c2c3a17e4635e80b1e1eb652f17e3608sha256: ae007486117352fe4d7f57961f202df4914aeaa6632babaef3e15bf89988ce19sha512: bef46db54c7364586497eb61789a391f548d3be1c9db368258836c2151bb301bc32b701aaa5b04577b3ffefdde038f8e0f1b2795ba4de76fd9c1f5cfd70e4d9fssdeep: 98304:xwL40vKNuBlawbeeg/BgWaf2VXu4wCdOFTCpspZd9F8JxVql0DWXtOwPf8O:xwL40vFlaKeeg/BgWaf2VXu4jsGspZdtype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709 (C) 1995-2004 x91d1x5c71x8f6fx4ef6x80a1x4efdx6709x9650x516cx53f8InternalName: GameFileVersion: 3, 0, 0, 6CompanyName: x91d1x5c71x8f6fx4ef6x80a1x4efdx6709x9650x516cx53f8PrivateBuild: LegalTrademarks: Comments: ProductName: SwordOnlineOLESelfRegister: SpecialBuild: ProductVersion: 3.00.00.2003FileDescription: JxOnline ClientOriginalFilename: Game.exeTranslation: 0x0804 0x04b0

Ursu.847078 also known as:

MicroWorld-eScan Gen:Variant.Ursu.847078
CAT-QuickHeal Trojan.MauvaiseRI.S5254690
McAfee GenericRXGB-QS!F857575C9CD5
Cylance Unsafe
K7AntiVirus Trojan ( 005203381 )
BitDefender Gen:Variant.Ursu.847078
K7GW Trojan ( 005203381 )
CrowdStrike win/malicious_confidence_100% (W)
TrendMicro TROJ_GEN.R002C0PEN20
Symantec ML.Attribute.HighConfidence
APEX Malicious
Avast Win32:Malware-gen
GData Gen:Variant.Ursu.847078
Kaspersky HEUR:Trojan.Win32.Quasar.gen
Alibaba Trojan:Win32/Quasar.1187b2be
AegisLab Trojan.Win32.Quasar.4!c
Ad-Aware Gen:Variant.Ursu.847078
Emsisoft Gen:Variant.Ursu.847078 (B)
F-Secure Trojan.TR/Redcap.azmui
McAfee-GW-Edition GenericRXGB-QS!F857575C9CD5
Trapmine malicious.moderate.ml.score
FireEye Generic.mg.f857575c9cd5c2bb
Sophos Mal/Generic-S
Jiangmin Trojan.Quasar.af
Webroot W32.Malware.Gen
Avira TR/Redcap.azmui
MAX malware (ai score=88)
Antiy-AVL Trojan/Win32.Quasar
Endgame malicious (high confidence)
Arcabit Trojan.Ursu.DCECE6
ZoneAlarm HEUR:Trojan.Win32.Quasar.gen
Microsoft Trojan:Win32/Occamy.C
Acronis suspicious
ALYac Gen:Variant.Ursu.847078
VBA32 Malware-Cryptor.Win32.General.4
Malwarebytes Backdoor.Quasar.Enigma
Panda Trj/CI.A
TrendMicro-HouseCall TROJ_GEN.R002C0PEN20
Rising Trojan.Quasar!8.F866 (CLOUD)
SentinelOne DFI – Malicious PE
MaxSecure Trojan.Malware.73867963.susgen
Fortinet W32/Quasar.QS!tr
BitDefenderTheta Gen:NN.ZexaF.34122.@F1@ae5bEUlj
AVG Win32:Malware-gen
Cybereason malicious.1c2c3a
Paloalto generic.ml
Qihoo-360 Win32/Trojan.4c5

How to remove Ursu.847078?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

How to remove “Doina.50383”?

The Doina.50383 is considered dangerous by lots of security experts. When this infection is active,…

11 mins ago

Should I remove “Babar.207736”?

The Babar.207736 is considered dangerous by lots of security experts. When this infection is active,…

12 mins ago

Trojan.Heur.omSfrOVW61pj removal tips

The Trojan.Heur.omSfrOVW61pj is considered dangerous by lots of security experts. When this infection is active,…

22 mins ago

Win32/Kryptik.HDSJ information

The Win32/Kryptik.HDSJ is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

MSIL/GameTool.U potentially unsafe removal

The MSIL/GameTool.U potentially unsafe is considered dangerous by lots of security experts. When this infection…

2 hours ago

Win32:VB-ABOX [Trj] removal guide

The Win32:VB-ABOX [Trj] is considered dangerous by lots of security experts. When this infection is…

2 hours ago