Malware

Ursu.920178 (file analysis)

Malware Removal

The Ursu.920178 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.920178 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Anomalous binary characteristics

How to determine Ursu.920178?


File Info:

crc32: 0DE3B0E1
md5: c49f7875fb17e83a933af241996f159a
name: C49F7875FB17E83A933AF241996F159A.mlw
sha1: cc54c06f8ebb051d201e75de2b0bbc7329331e23
sha256: 4da4f627c30045c8f84870abb3618ec05141a7ff76f7cd346c73dcd2cd846caa
sha512: 6d5253659d9ed344ccf50db85c1b17a418665f9503b85771159b9facef1369c8d68c9932d667783870280c6f4bcbe9e0afa595f5883e3aa5ce8f7ba38ca7961b
ssdeep: 12288:pqmZq25C0y+qM4wlR6Qb2p/hRrAR1inUcihIaiha:Nq25sClnap5A1iUcxai4
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: AQQ Sp.
FileVersion: 2.4
CompanyName: AQQ Sp. z o.o.
LegalTrademarks: AQQ Sp. z1
ProductName: AQQ IMM
ProductVersion: 1.0.0.1
OriginalFilename: AQQSp.exe
Translation: 0x0409 0x04e4

Ursu.920178 also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanGen:Variant.Ursu.920178
McAfeeGenericRXDZ-EC!C49F7875FB17
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004f32c81 )
BitDefenderGen:Variant.Ursu.920178
K7GWTrojan ( 004f32c81 )
Cybereasonmalicious.5fb17e
BitDefenderThetaGen:NN.ZexaF.34590.Cu1@aKHpqBdi
CyrenW32/S-5217633b!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.FBEK
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Foreign.nxhk
NANO-AntivirusTrojan.Win32.Panda.ewusim
AegisLabTrojan.Win32.Generic.4!c
TencentWin32.Trojan.Foreign.Syhz
Ad-AwareGen:Variant.Ursu.920178
EmsisoftGen:Variant.Ursu.920178 (B)
ComodoTrojWare.Win32.Zbot.EZXT@7tgdwr
F-SecureHeuristic.HEUR/AGEN.1112597
DrWebTrojan.PWS.Panda.13211
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.c49f7875fb17e83a
SophosMal/Generic-R + Mal/Ransom-EE
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1112597
MAXmalware (ai score=98)
Antiy-AVLTrojan[Ransom]/Win32.Foreign
MicrosoftPWS:Win32/Zbot
ArcabitTrojan.Ursu.DE0A72
AhnLab-V3Spyware/Win32.Zbot.C2282440
ZoneAlarmTrojan-Ransom.Win32.Foreign.nxhk
GDataGen:Variant.Ursu.920178
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.920178
MalwarebytesMalware.AI.3526434484
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.100 (RDML:eDPunJp1qlnGOowRMPYlJQ)
YandexTrojan.Foreign!DMmwsxlb+v0
IkarusTrojan-Ransom.Foreign
eGambitUnsafe.AI_Score_99%
FortinetW32/Kryptik.FCAB!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (D)
Qihoo-360Win32/Backdoor.Zbot.J

How to remove Ursu.920178?

Ursu.920178 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment