Categories: Malware

About “Ursu.873667” infection

The Ursu.873667 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.873667 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests

Related domains:

inno.bisrv.com
www.hugedomains.com

How to determine Ursu.873667?


File Info:

crc32: E7FB2131md5: 21efc865527536b665359e8f45177245name: 21EFC865527536B665359E8F45177245.mlwsha1: df264f4d3a70a8f8348549a82c9ebea3f01f5ad1sha256: cb60f5ab9fab43e0f760522481bca9c0418c835b5cb493f41055aed3f3416b79sha512: 20ed47aaaf16dfd9f7cbb5988a15ffebf7726a73fa46d6e9fae01e2489fdcca8b28385b6cbc6ff79ef1213ee53f31dda3db8ce01a646a891dd95a0cae148a817ssdeep: 12288:CQiG5zL8+iDNdROX2VZng4I6VJs+Rl7q3C8pJth:CQic38Ddo2jg4X/l7uhtype: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: FileVersion: CompanyName: Homebrew Projects Comments: This installation was built with Inno Setup.ProductName: Ultimate Facebook Hacker ProductVersion: 3.5.1 FileDescription: Ultimate Facebook Hacker Setup Translation: 0x0000 0x04b0

Ursu.873667 also known as:

K7AntiVirus Trojan ( 0052470c1 )
ALYac Gen:Variant.Ursu.873667
Cylance Unsafe
Zillya Tool.FBTools.Win32.1
Sangfor Hacktool.Win32.FBTools.a
K7GW Trojan ( 0052470c1 )
Cybereason malicious.552753
Symantec Trojan.Gen.MBT
ESET-NOD32 multiple detections
APEX Malicious
Avast Win32:PUP-gen [PUP]
Kaspersky HackTool.Win32.FBTools.a
BitDefender Gen:Variant.Ursu.873667
NANO-Antivirus Trojan.Win32.FBTools.brczrl
MicroWorld-eScan Gen:Variant.Ursu.873667
Tencent Win32.Hacktool.Fbtools.Hrpn
Sophos Generic PUA NP
Comodo Malware@#1s4l3458o0fmw
VIPRE MSIL.Hoax.FakeHack (not malicious)
McAfee-GW-Edition BehavesLike.Win32.PUPInstaller.hc
FireEye Gen:Variant.Ursu.873667
Emsisoft Gen:Variant.Ursu.873667 (B)
Webroot W32.Malware.Heur
Antiy-AVL Trojan/Generic.ASMalwS.2CFCFE
Kingsoft Win32.HackTool.Undef.(kcloud)
Microsoft Trojan:Win32/Wacatac.A!ml
GData Gen:Variant.Ursu.873667
McAfee Artemis!21EFC8655275
MAX malware (ai score=99)
Panda Trj/CI.A
TrendMicro-HouseCall TROJ_GEN.R002H0CKA21
Yandex Riskware.HackTool!0EALuwYx5YU
Fortinet Riskware/Hack
AVG Win32:PUP-gen [PUP]
Paloalto generic.ml

How to remove Ursu.873667?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Trojan.Dropper.VPA malicious file

The Trojan.Dropper.VPA is considered dangerous by lots of security experts. When this infection is active,…

48 seconds ago

Malware.AI.1545899637 malicious file

The Malware.AI.1545899637 is considered dangerous by lots of security experts. When this infection is active,…

8 mins ago

Trojan:Win32/Strab.GPG!MTB removal guide

The Trojan:Win32/Strab.GPG!MTB is considered dangerous by lots of security experts. When this infection is active,…

26 mins ago

Trojan.Win32.Agent.xbocpf removal

The Trojan.Win32.Agent.xbocpf is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

What is “Malware.AI.4092848701”?

The Malware.AI.4092848701 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

About “Trojan.Generic.35764356” infection

The Trojan.Generic.35764356 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago