Malware

What is “Ursu.949587 (B)”?

Malware Removal

The Ursu.949587 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.949587 (B) virus can do?

  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with ASPack
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Ursu.949587 (B)?


File Info:

name: C6A4BDC484E7EC48974A.mlw
path: /opt/CAPEv2/storage/binaries/990d95dcf930bdcb10d6fc60d5037045a102658b62216906840091381554e832
crc32: 9F4F3382
md5: c6a4bdc484e7ec48974aaa7ee1e539ee
sha1: b2b78d6882aec0a3aae8e08059f6b5ce1698b9a0
sha256: 990d95dcf930bdcb10d6fc60d5037045a102658b62216906840091381554e832
sha512: 56d9200e3a96e5aa4097ba2a4151832664d2aa5ebbd14579573c1f38ea98717a85b8cec62e4d9539c43003b0765ad2e99af0eb9bfa63f9963e698a9e52e2d246
ssdeep: 12288:DU2gxht7KeXZ3H+Hm6RVSeKzp8TSjATcMt2x8BuWVUVR56FmOJRVhvj:w2jeNEm62JdUIATBt2xmuOo6kal
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T142D42395D6B4798ECCD423F9899297328B1ADFF05AE1753630A05C9F22BF1212C78BC5
sha3_384: 8d309607d7ca75d2fb0f545f1500568dbb6ae53ed144e695a57eb254b612fb9ba190e882f5aad9fca47b2c98fd256b7b
ep_bytes: 60e803000000e9eb045d4555c3e80100
timestamp: 1992-06-19 22:22:17

Version Info:

CompanyName: 天宇科技
FileDescription: CH投票软件
FileVersion: 8.12.0.0
InternalName: QQ9810736
LegalCopyright:
LegalTrademarks:
OriginalFilename:
ProductName:
ProductVersion: 1.0.0.0
Comments:
Translation: 0x0804 0x03a8

Ursu.949587 (B) also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ursu.949587
FireEyeGeneric.mg.c6a4bdc484e7ec48
McAfeeArtemis!C6A4BDC484E7
CylanceUnsafe
K7AntiVirusTrojan ( 7000000f1 )
AlibabaMalware:Win32/km_2b06806.None
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.484e7e
BitDefenderThetaGen:NN.ZexaF.34160.LO0baKAzU4kb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/RiskWare.HangVote.J
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
BitDefenderGen:Variant.Ursu.949587
TencentWin32.Trojan.Ursu.Szlc
Ad-AwareGen:Variant.Ursu.949587
EmsisoftGen:Variant.Ursu.949587 (B)
McAfee-GW-EditionBehavesLike.Win32.BadFile.jc
SophosMal/Generic-S
GDataGen:Variant.Ursu.949587
eGambitUnsafe.AI_Score_100%
AviraHEUR/AGEN.1109876
Antiy-AVLRiskWare/Win32.HangVote
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
VBA32BScope.Trojan.Bitrep
ALYacGen:Variant.Ursu.949587
MAXmalware (ai score=80)
MalwarebytesMalware.AI.2387482594
TrendMicro-HouseCallTROJ_GEN.R03BH09AD22
RisingMalware.Heuristic!ET#98% (RDMK:cmRtazrEHoEPQlo7tGmQ4PrJLmF6)
SentinelOneStatic AI – Suspicious PE
FortinetRiskware/HangVote
AVGWin32:Malware-gen

How to remove Ursu.949587 (B)?

Ursu.949587 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment