Malware

How to remove “Ser.Ursu.12324”?

Malware Removal

The Ser.Ursu.12324 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Ursu.12324 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Collects information to fingerprint the system

Related domains:

z.whorecord.xyz
0.tcp.ngrok.io
a.tomx.xyz

How to determine Ser.Ursu.12324?


File Info:

crc32: F099F7D6
md5: dd647c179fae75262e8c2a8a3bd433e3
name: keepalive.exe
sha1: 768f0723d57dcd9a83bb66b16451c12d50c81f89
sha256: f167685c3f56500736c2946ef25ddffe3e7a8b6b92d30c3d065bebfdbae70d73
sha512: db99b7f472e3d8f03f85a32967d4b446ccda449e83a00c2eb6738107c076e984d57774bca0235383cb5f7fbf1a344fd54a7ad5626b08d068e96228100eb46e20
ssdeep: 768:OH8uB5ctp7bP/fUR+ENIvfONqE5/BN0zflXopTTiYDY2TsfzYcHe+Z:scz7LfUR+IIvmA45K7VoFOte+
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: Copyright xc2xa9 Nightmare 2016
InternalName: Nightmare.exe
FileVersion: 0.0.0.3
CompanyName: Nightmare
LegalTrademarks: Nightmare
ProductName: Nightmare
ProductVersion: 0.0.0.3
FileDescription: Nightmare
OriginalFilename: Nightmare.exe
Translation: 0x0409 0x04b0

Ser.Ursu.12324 also known as:

MicroWorld-eScanGen:Variant.Ser.Ursu.12324
FireEyeGeneric.mg.dd647c179fae7526
CAT-QuickHealTrojan.MSIL
Qihoo-360Generic/Trojan.3f2
McAfeeTrojan-FSIH!DD647C179FAE
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005121fb1 )
BitDefenderGen:Variant.Ser.Ursu.12324
K7GWTrojan ( 005121fb1 )
CrowdStrikewin/malicious_confidence_90% (W)
Invinceaheuristic
SymantecTrojan.Revetrat
APEXMalicious
ClamAVWin.Trojan.Generic-6332612-0
GDataGen:Variant.Ser.Ursu.12324
KasperskyHEUR:Trojan.MSIL.RRAT.gen
AlibabaTrojan:MSIL/Generic.d03490b8
AegisLabTrojan.MSIL.RRAT.4!c
RisingTrojan.Agent!8.B1E (CLOUD)
Endgamemalicious (high confidence)
EmsisoftGen:Variant.Ser.Ursu.12324 (B)
ComodoMalware@#2mqyu13ijnl2g
F-SecureHeuristic.HEUR/AGEN.1128452
DrWebBackDoor.SpyBotNET.20
TrendMicroTROJ_GEN.R002C0PER20
McAfee-GW-EditionTrojan-FSIH!DD647C179FAE
SophosMal/Revet-A
IkarusBackdoor-Rat.Revenge
AviraHEUR/AGEN.1128452
MAXmalware (ai score=81)
Antiy-AVLTrojan/MSIL.RRAT
ArcabitTrojan.Ser.Ursu.D3024
ZoneAlarmHEUR:Trojan.MSIL.RRAT.gen
MicrosoftTrojan:Win32/Vigorf.A
AhnLab-V3Trojan/Win32.Dynamer.C1778161
Ad-AwareGen:Variant.Ser.Ursu.12324
MalwarebytesBackdoor.RevengeRAT
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Agent.AZM
TrendMicro-HouseCallTROJ_GEN.R002C0PER20
TencentWin32.Trojan.Generic.Wtng
SentinelOneDFI – Malicious PE
eGambitTrojan.Generic
FortinetMSIL/Agent.AZM!tr
BitDefenderThetaGen:NN.ZemsilF.34122.dq0@amtvzfbi
AVGFileRepMalware
Cybereasonmalicious.79fae7
Paloaltogeneric.ml

How to remove Ser.Ursu.12324?

Ser.Ursu.12324 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment