Malware

Ursu.922142 removal instruction

Malware Removal

The Ursu.922142 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.922142 virus can do?

  • Creates RWX memory
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz

How to determine Ursu.922142?


File Info:

crc32: A186847B
md5: 69b292d6d8e518ae1b1e9d1696b032bd
name: 69B292D6D8E518AE1B1E9D1696B032BD.mlw
sha1: 6bbe410d6251c1a74c14d1b13b2a09db25ff1ae2
sha256: 2c6089e2696d7c8c76e128cf433b91f20ba205cc22bca516f570ec55ed20990e
sha512: ad049744a21adfd125fd692d0085721365ad54124ed915bdf1dfa0836a6f1f945c2d4a86e40f35cae92e2489996acea36846c6bf908b6247103e106594abf711
ssdeep: 49152:bjEGd6OmfITiV4oanhqAlDfQD07rL9Bp:PEGdmfITiJanhqA1YDirpB
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright by Kungho Technology
InternalName:
FileVersion: 1.0.0.661
CompanyName: Chengdu Kungho Technology Co,. Ltd.
LegalTrademarks:
Comments: x514dx8d39x7248x672c
ProductName: Kungho ADP-System
ProductVersion: 1.0.0.0
FileDescription: Kungho ADP-System Core
OriginalFilename: KHCore.exe
Translation: 0x0804 0x03a8

Ursu.922142 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.922142
CylanceUnsafe
SangforTrojan.Win32.Save.a
AlibabaBackdoor:Win32/OnlineGames.0bb81aaa
Cybereasonmalicious.6d8e51
CyrenW32/OnlineGames.CE.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
BitDefenderGen:Variant.Ursu.922142
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanGen:Variant.Ursu.922142
Ad-AwareGen:Variant.Ursu.922142
ComodoTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
BitDefenderThetaGen:NN.ZelphiCO.34170.MnKfaSVZnemb
VIPRETrojan.Win32.OnlineGames
McAfee-GW-EditionBehavesLike.Win32.Dropper.tc
FireEyeGeneric.mg.69b292d6d8e518ae
EmsisoftGen:Variant.Ursu.922142 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1130921
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.B653CB
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Ursu.922142
McAfeeArtemis!69B292D6D8E5
MAXmalware (ai score=99)
VBA32BScope.Backdoor.Hupigon
RisingBackdoor.Farfli!1.6542 (CLASSIC)
IkarusBackdoor.Win32.Hupigon
FortinetW32/Generic!tr.bdr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Ursu.922142?

Ursu.922142 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment