Malware

What is “Ursu.97246”?

Malware Removal

The Ursu.97246 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.97246 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Attempts to disable Windows Defender
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.97246?


File Info:

crc32: CCF804AB
md5: c962422ac6b045e6188ca6f3dd0c5b02
name: C962422AC6B045E6188CA6F3DD0C5B02.mlw
sha1: bad5c31214a4cc4f7d3271ad7dcfe4c941546836
sha256: 5f3b9bd0350429381f2b9f0f3b491178a02bbc8857c395166f3627cdae7af267
sha512: 836f9d2cec06c6c2ecef17ab1230fb340d20e9bbd21955fa3f14cd1359f1df2819e1736fc2e79737611cac4468b0a0512ad5dda7fb3d2d5325c44ecec0eb378c
ssdeep: 6144:ctyPiyPfGiGjXCHbDiXszU9Nbm0a2v1sAbbPL7yAEh2wyP5:ctdDiGDCzU9Nbm0/Kg8hNM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
LegalCopyright: xa9 2006-2018 MiniIn COF.
InternalName: EXMHNYQ
FileVersion: 1.00.0071
CompanyName: Kimble
ProductName: EXMHNYQ
ProductVersion: 1.00.0071
FileDescription: Unscramble this word and solve puzzles
OriginalFilename: EXMHNYQ.exe

Ursu.97246 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusEmailWorm ( 003c363a1 )
DrWebTrojan.Trick.45194
CynetMalicious (score: 100)
CAT-QuickHealTrojan.MansaboVMF.S21201718
ALYacGen:Variant.Ursu.97246
CylanceUnsafe
ZillyaTrojan.Mansabo.Win32.459
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaTrojan:Win32/Mansabo.f102a9aa
K7GWEmailWorm ( 003c363a1 )
Cybereasonmalicious.ac6b04
CyrenW32/S-2895d144!Eldorado
SymantecPacked.Generic.558
ESET-NOD32a variant of Win32/Injector.DVWK
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.TrickBot-9845695-1
KasperskyTrojan.Win32.Mansabo.asc
BitDefenderGen:Variant.Ursu.97246
NANO-AntivirusTrojan.Win32.Trick.eyaolc
MicroWorld-eScanGen:Variant.Ursu.97246
TencentMalware.Win32.Gencirc.10ba59f8
Ad-AwareGen:Variant.Ursu.97246
SophosMal/Generic-R + Troj/VB-JPY
ComodoMalware@#2wapl9gadqbu5
BitDefenderThetaGen:NN.ZevbaF.34266.wm0@aGKzxAEO
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.c962422ac6b045e6
EmsisoftGen:Variant.Ursu.97246 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Mansabo.tg
AviraHEUR/AGEN.1131919
Antiy-AVLTrojan/Generic.ASMalwS.247AEA4
MicrosoftTrojan:Win32/Totbrick.H
GDataGen:Variant.Ursu.97246
TACHYONTrojan/W32.VB-Mansabo.360448.B
AhnLab-V3Trojan/Win32.Trickbot.C2408908
Acronissuspicious
McAfeeGenericRXEB-DK!C962422AC6B0
MAXmalware (ai score=88)
VBA32Trojan.Mansabo
MalwarebytesSpyware.TrickBot
PandaTrj/Genetic.gen
YandexTrojan.GenAsa!gx2Kme8fgpQ
IkarusTrojan.Win32.Krypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.DVWK!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ursu.97246?

Ursu.97246 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment