Malware

Ursu.863801 (B) removal

Malware Removal

The Ursu.863801 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.863801 (B) virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Russian
  • Uses Windows utilities for basic functionality
  • Attempts to restart the guest VM
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
edgedl.me.gvt1.com
update.googleapis.com

How to determine Ursu.863801 (B)?


File Info:

crc32: A8BA2C7C
md5: 4509f3d8e8c8e70cf03bc724c4f57788
name: 4509F3D8E8C8E70CF03BC724C4F57788.mlw
sha1: 910835abe5b5ab6e756449b519a0fbc742389443
sha256: c7e9f970edb5c4b5968589722e03d43f5c9279022b718aa2bc9241f63bf85954
sha512: 2e5dd76fa22c4fca6571b91282a185314f91e60b4e0034eb3ea9f91be9da1d5f6f986951f98bbc900c4db72ca12a6985e8dd112c7bd60701381e1bc4fecb2a6e
ssdeep: 3072:86mU6pFwhRgYfmVG5I1r6jpOm3gr3uknoA/q63mWMPnP/2i42fHwFK7GSTz5Q42:86mU6pFwhRgY4G5I1re/kuhFTPnP/Lt
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 2011
InternalName: Mystic
FileVersion: 2.0
CompanyName: x41ex41ex41e x417x430x43ax440x438x43fx442x443x439
ProductName: The space invader corp.
ProductVersion: 2.0))
FileDescription: Mystic compressor
OriginalFilename: Mystic

Ursu.863801 (B) also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0023944d1 )
LionicTrojan.Win32.HmBlocker.j!c
DrWebTrojan.Packed.1974
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.863801
CylanceUnsafe
ZillyaTrojan.HmBlocker.Win32.365
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaRansom:Win32/HmBlocker.cbb93d96
K7GWTrojan ( 0023944d1 )
Cybereasonmalicious.8e8c8e
CyrenW32/S-4cceb572!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.MHS
APEXMalicious
AvastWin32:Mystic
KasperskyTrojan-Ransom.Win32.HmBlocker.djm
BitDefenderGen:Variant.Ursu.863801
NANO-AntivirusTrojan.Win32.Winlock.ccxqk
ViRobotTrojan.Win32.A.HmBlocker.129536.B
MicroWorld-eScanGen:Variant.Ursu.863801
TencentWin32.Trojan.Hmblocker.Ozsb
Ad-AwareGen:Variant.Ursu.863801
SophosML/PE-A + Mal/FakeAV-MR
ComodoMalware@#3ligz5ajoajol
BitDefenderThetaGen:NN.ZexaF.34058.lu0@aO7Hs4eU
VIPRETrojan.Win32.FakeAV.gq (v)
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.4509f3d8e8c8e70c
EmsisoftGen:Variant.Ursu.863801 (B)
JiangminTrojan/HmBlocker.ant
AviraTR/Crypt.XPACK.Gen
eGambitGeneric.Downloader
Antiy-AVLTrojan/Generic.ASMalwS.18BC2AA
MicrosoftTrojan:Win32/Bulta!rfn
GDataGen:Variant.Ursu.863801
McAfeeArtemis!4509F3D8E8C8
MAXmalware (ai score=100)
VBA32Trojan.ExpProc.014
MalwarebytesMalware.AI.3599739892
PandaGeneric Malware
RisingTrojan.Generic@ML.100 (RDML:KITMGLp0oTcMp0TZJwQ/ag)
YandexTrojan.HmBlocker!QhdxeyQIzdc
IkarusTrojan-Ransom.HmBlocker
FortinetW32/Yakes.S!tr
AVGWin32:Mystic
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.PornoBlocker.HxQBEpsA

How to remove Ursu.863801 (B)?

Ursu.863801 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment