Malware

Ursu.911784 (B) removal guide

Malware Removal

The Ursu.911784 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.911784 (B) virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • A named pipe was used for inter-process communication
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Checks the version of Bios, possibly for anti-virtualization
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

www.ip-adress.com

How to determine Ursu.911784 (B)?


File Info:

crc32: 531BEFC2
md5: 4ec5b480f56d2f6cf44b832694cfe105
name: 88888.png
sha1: 60520dac62fa9b530a688c7bdbfb146549498878
sha256: 08e52a966ea59d62ed8333a8299a0534b950107abfabfa75ad5f0e0d4d763d34
sha512: 0d111542bf8ccc4bae6e4468e475ccab9f6b8b332796827f4910edacbd781e07bc9bbb7bd35a6f25e1558d5ac0ce3a4594aa14adad59c1556de09b7fb82d0b77
ssdeep: 12288:0lQB2wwLHqpVxT85LfHbRhco5QFuo+NCYkfgn6ggKENK:T2wwTX5Ldhf5QUo+NRkfg93EU
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2015 ZPN
InternalName: ZPN Connect
FileVersion: 2.0.2.0
CompanyName: ZPN
LegalTrademarks1: All Rights Reserved
LegalTrademarks2: All Rights Reserved
ProductName: ZPN Connect v1
ProductVersion: 2.0.2
FileDescription: ZPN Connect
OriginalFilename: ZpnCli.exe
Translation: 0x0409 0x04e4

Ursu.911784 (B) also known as:

BkavW32.AIDetectVM.malwareB
MicroWorld-eScanGen:Variant.Ursu.911784
FireEyeGeneric.mg.4ec5b480f56d2f6c
McAfeeW32/PinkSbot-GW!4EC5B480F56D
CylanceUnsafe
SangforMalware
BitDefenderGen:Variant.Ursu.911784
CrowdStrikewin/malicious_confidence_100% (D)
Invinceaheuristic
APEXMalicious
GDataGen:Variant.Ursu.911784
Endgamemalicious (high confidence)
SophosTroj/Qbot-FS
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Ursu.911784 (B)
SentinelOneDFI – Malicious PE
Antiy-AVLGrayWare/Win32.Kryptik.ehls
ArcabitTrojan.Ursu.DDE9A8
Acronissuspicious
VBA32BScope.TrojanRansom.Shade
MAXmalware (ai score=81)
Ad-AwareGen:Variant.Ursu.911784
MalwarebytesBackdoor.Qbot
ESET-NOD32a variant of Win32/GenKryptik.EMQL
RisingMalware.Heuristic!ET#84% (RDMK:cmRtazoalBZRT0pCk3PDFBo6KdB6)
eGambitPE.Heur.InvalidSig
FortinetW32/QBOT.CC!tr
BitDefenderThetaGen:NN.ZexaF.34128.NI1@aiOZdmai

How to remove Ursu.911784 (B)?

Ursu.911784 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment