Malware

Ursu.946963 (B) (file analysis)

Malware Removal

The Ursu.946963 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.946963 (B) virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.946963 (B)?


File Info:

crc32: 693A7E53
md5: df4a79c655fe8d6106e5e29c8e979eb4
name: DF4A79C655FE8D6106E5E29C8E979EB4.mlw
sha1: f42dd3c0f0d5a2f7916c89f9c3bca4dcdaa09583
sha256: 1a6b49c1183b751d84bf79dc43e66889313344246579d937f0c029fc6a7169b3
sha512: 8d1a770cdbb94735df2c57fb3c30de88dd81b21ac8b4da89eb093deab1adff02eebde2353f6039d64d2c0687388821b33e650ce9d739680eab738d0743501cde
ssdeep: 24576:+2niW96H0dBXv0K+JtTFA96H039JJd3n+Otv2K5iP7iS3j3n4JJRJJJyAVJfJJG:+8irHeBMK+JLNHqOyCPOSzQB7COyCPO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) Microsoft Corp. 1981-2000
InternalName: copymar
FileVersion: 6.10.0016.1624
CompanyName: Microsoft Corporation
Built by: msnbld
ProductName: Microsoft(R) MSN (R) Communications System
ProductVersion: 6.10.0016.1624
FileDescription: copymar
OriginalFilename: copymar.exe
Translation: 0x0409 0x04b0

Ursu.946963 (B) also known as:

BkavW32.AIDetect.malware1
K7AntiVirusRiskware ( 0040eff71 )
LionicRiskware.Win32.Generic.1!c
Elasticmalicious (high confidence)
ALYacGen:Variant.Ursu.946963
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderGen:Variant.Ursu.946963
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.655fe8
CyrenW32/Vigua.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
CynetMalicious (score: 100)
AlibabaWorm:Win32/Mabezat.735e54f1
MicroWorld-eScanGen:Variant.Ursu.946963
Ad-AwareGen:Variant.Ursu.946963
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34236.6o3@aa6FvTpi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Virut.vh
FireEyeGeneric.mg.df4a79c655fe8d61
EmsisoftGen:Variant.Ursu.946963 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1117843
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Ursu.DE7313
GDataWin32.Trojan.PSE.1WFDCAS
McAfeeTrojan-FQDC!DF4A79C655FE
IkarusWorm.Win32.Mabezat
FortinetW32/Trojan.FQDC!tr
Paloaltogeneric.ml

How to remove Ursu.946963 (B)?

Ursu.946963 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment