Malware

What is “Ursu.930540”?

Malware Removal

The Ursu.930540 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.930540 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Starts servers listening on 0.0.0.0:39778
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Looks up the external IP address
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to create or modify system certificates
  • Generates some ICMP traffic
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

Related domains:

google.de
checkip.dyndns.org
www.infosniper.net
sahnepan2.u2m.ru

How to determine Ursu.930540?


File Info:

crc32: 45301732
md5: d38ab335607461a33c52116575dfa5bd
name: D38AB335607461A33C52116575DFA5BD.mlw
sha1: 071ca8554cb68cfe2dab483520b16b2fbb323377
sha256: 6b70d75a6b6a1b93e133c2c8d80046dab7771275c779bf0ecd8ccf2e84ec984c
sha512: 690bb14b821cac5917aebdcabbf7044cec1d24f92a94cc0ce7fa6237139be6347daa1dde2c6659ca74af1aeb8c1ec0bf30c5b6e4e7366f993469d16305e623b3
ssdeep: 6144:OSemaYysQBEDBH1rsp/ZvTx3tJku1i515mcHp44ewzznGNbukS/Ixl3JqW:OSCpBddJku1acMprzzqp
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2012
Assembly Version: 1.0.0.0
InternalName: Rev_5.exe
FileVersion: 1.0.0.0
ProductName: Rev_5
ProductVersion: 1.0.0.0
FileDescription: Rev_5
OriginalFilename: Rev_5.exe

Ursu.930540 also known as:

K7AntiVirusRiskware ( 0040eff71 )
DrWebTrojan.DownLoader7.42565
ALYacGen:Variant.Ursu.930540
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1094367
SangforTrojan.Win32.AGEN.1033330
AlibabaRansom:Win32/Blocker.db6f4ba6
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.560746
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Agent.OJQ
APEXMalicious
AvastWin32:Dropper-gen [Drp]
KasperskyTrojan-Ransom.Win32.Blocker.wqm
BitDefenderGen:Variant.Ursu.930540
NANO-AntivirusTrojan.Win32.RiskGen.cwrrbm
MicroWorld-eScanGen:Variant.Ursu.930540
TencentWin32.Trojan.Blocker.Wqms
Ad-AwareGen:Variant.Ursu.930540
ComodoMalware@#lmj820d99ls8
BitDefenderThetaGen:NN.ZemsilF.34684.xm0@aO@@AOp
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.d38ab335607461a3
EmsisoftGen:Variant.Ursu.930540 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.nif
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1127088
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftBackdoor:Win32/Bladabindi!ml
AegisLabTrojan.Win32.Blocker.4!c
ZoneAlarmTrojan-Ransom.Win32.Blocker.wqm
GDataGen:Variant.Ursu.930540
McAfeeArtemis!D38AB3356074
MAXmalware (ai score=100)
VBA32Hoax.Blocker
PandaGeneric Malware
RisingRansom.Blocker!8.12A (CLOUD)
IkarusTrojan-Ransom.Blocker
FortinetW32/Blocker.WQM!tr
AVGWin32:Dropper-gen [Drp]
Paloaltogeneric.ml

How to remove Ursu.930540?

Ursu.930540 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment