Malware

About “Ursu.946755 (B)” infection

Malware Removal

The Ursu.946755 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.946755 (B) virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Presents an Authenticode digital signature
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Detects Sandboxie through the presence of a library
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
a.tomx.xyz
repository.certum.pl

How to determine Ursu.946755 (B)?


File Info:

crc32: 6973C686
md5: 5c3196999e7c886aaaa3368e6f077bba
name: 5C3196999E7C886AAAA3368E6F077BBA.mlw
sha1: dcd63a6e13dec228cd7ae71fd1a673596457d187
sha256: 989cae7a33e370595b5fa3970422aa5996041f03f1adf1a7d0867c3233732e87
sha512: e7cf2ad5961d72161db95b63aa5ed654e40f8a130e417e5db657a76d7458efa6906f78c7cfb1d35118a5cd3a6150c0de2d8d8e3d0d00d192385672122c4fcd1a
ssdeep: 24576:ia3srLcLYH0ry+JHmy1d6k+yEo5t74IYGJOTO:z3srLcL40rlm68CT/Oq
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2013 - 2021 Yamato Ryou Inc.
FileVersion: 1.2.25.0
CompanyName: Yamato Ryou Inc.
Comments: FL Studio x90e8x7f72x7a0bx5e8f
ProductName: FL Studio x90e8x7f72x7a0bx5e8f
ProductVersion: 1.2.25.0
FileDescription: FL Studio x90e8x7f72x7a0bx5e8f
Translation: 0x0804 0x04b0

Ursu.946755 (B) also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005246d51 )
Elasticmalicious (high confidence)
ALYacGen:Variant.Ursu.946755
CylanceUnsafe
SangforTrojan.Win32.Wacatac.B
BitDefenderGen:Variant.Ursu.946755
K7GWTrojan ( 005246d51 )
Cybereasonmalicious.99e7c8
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 99)
MicroWorld-eScanGen:Variant.Ursu.946755
Ad-AwareGen:Variant.Ursu.946755
SophosGeneric PUA NM (PUA)
BitDefenderThetaGen:NN.ZexaF.34770.bnLfamNQE9cb
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Ursu.946755
EmsisoftGen:Variant.Ursu.946755 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1136189
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASCommon.FA
GDataGen:Variant.Ursu.946755
Acronissuspicious
McAfeeGenericRXAA-AA!5C3196999E7C
MAXmalware (ai score=84)
MalwarebytesMalware.AI.1988891458
TrendMicro-HouseCallTROJ_GEN.R002H09FS21
MaxSecureTrojan.Malware.300983.susgen
FortinetRiskware/Application
Qihoo-360Win32/Trojan.Generic.HgIASXYA

How to remove Ursu.946755 (B)?

Ursu.946755 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment