Malware

How to remove “Ursu.949587”?

Malware Removal

The Ursu.949587 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.949587 virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Anomalous binary characteristics

How to determine Ursu.949587?


File Info:

crc32: 6A5AADDC
md5: 05f190f34ab784691e2478667ca2ba4a
name: 05F190F34AB784691E2478667CA2BA4A.mlw
sha1: c360511ada0b70f894d67d7619ac874f3bd30b39
sha256: 5fe8f681d5b55913758a9368b3541bcb1d63e8e78417c503f689d49851135ce7
sha512: 41326d026c9495316d55cf24ced7b3c1908e3d010cff4b8ea5ec85eefd9540e4528a306731127a972c9ace6a562988f3acacb2645cef606b8bb2c586c1262a76
ssdeep: 6144:0yF3xUe/RI6uK9iaYelqP/lpw12mnonLO6nvDO4pF0CEwfuElOttI1sVJ2X:0y1xU0I6uunCgSny6rd0ChTYttI+
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName: QQ9810736
FileVersion: 8.12.0.0
CompanyName: x5929x5b87x79d1x6280
LegalTrademarks:
Comments:
ProductName:
ProductVersion: 1.0.0.0
FileDescription: CHx6295x7968x8f6fx4ef6
OriginalFilename:
Translation: 0x0804 0x03a8

Ursu.949587 also known as:

K7AntiVirusTrojan ( 7000000f1 )
Elasticmalicious (high confidence)
CynetMalicious (score: 99)
CAT-QuickHealTrojan.Generic.S525138
ALYacGen:Variant.Ursu.949587
CylanceUnsafe
AlibabaRiskWare:Win32/HangVote.177367fb
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.34ab78
CyrenW32/S-41bae044!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/RiskWare.HangVote.J
APEXMalicious
AvastWin32:Malware-gen
BitDefenderGen:Variant.Ursu.949587
MicroWorld-eScanGen:Variant.Ursu.949587
Ad-AwareGen:Variant.Ursu.949587
SophosGeneric PUA MD (PUA)
BitDefenderThetaGen:NN.ZexaF.34266.AO0baywqqygb
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGen:Variant.Ursu.949587
EmsisoftGen:Variant.Ursu.949587 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1109876
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.2696AFD
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Wacatac.A!ml
GDataGen:Variant.Ursu.949587
AhnLab-V3Malware/Win32.RL_Generic.R304706
McAfeeArtemis!05F190F34AB7
MAXmalware (ai score=98)
VBA32BScope.Backdoor.Attack
MalwarebytesMalware.AI.2387482594
PandaTrj/Genetic.gen
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazorAL7OdX3nZESsZiLXI6LF)
YandexTrojan.GenAsa!ZFxQXQp5ezA
IkarusBackdoor.Win32.Hupigon
FortinetW32/GenericRXDZ.UV!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ursu.949587?

Ursu.949587 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment