Malware

Ursu.12444 removal guide

Malware Removal

The Ursu.12444 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.12444 virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Behavior consistent with a dropper attempting to download the next stage.
  • Anomalous binary characteristics

Related domains:

chubbyoasis.top
strangerthingz.club

How to determine Ursu.12444?


File Info:

crc32: 7B89B1E3
md5: 82bd30240f7605d2c5675e17998661a0
name: 82BD30240F7605D2C5675E17998661A0.mlw
sha1: b59f753a5bc4142a01c3cab561bc4e59daae8dfb
sha256: dd253d8169d6dbc8fc906054ef91dbb67a82a5dda4b72108a2b2485f0bc49ac9
sha512: e6251f162a5075179879a9fe1f62d675262cd73d54f776dcb4602a0ce8625308ef093a837ac63f04aa977840ec385cfb0b8d404a4b7971c41cb2f66db256d1f8
ssdeep: 3072:GrV1c41UtsubOpx55lhpG4C6lkZlbwoKwTLpl+Ake3V/cpvrtE0A/:Go4UZOpx55lhNC6lUa2LiGVcI
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: foxw iStoneProds 4 All rights reserved.
InternalName: w1w4q Content Installer 9
FileVersion: 8.140.31.187
CompanyName:
Comments: bfv Install software 99
ProductName: az2 NSIS 32 installer
ProductVersion: 8.140.31.187
Translation: 0x0409 0x04b0

Ursu.12444 also known as:

BkavW32.AIDetectVM.malware1
MicroWorld-eScanGen:Variant.Ursu.12444
FireEyeGeneric.mg.82bd30240f7605d2
McAfeeArtemis!82BD30240F76
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan-Downloader ( 0051a6c11 )
BitDefenderGen:Variant.Ursu.12444
K7GWTrojan-Downloader ( 0051a6c11 )
Cybereasonmalicious.40f760
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Tovkater-6646868-0
KasperskyTrojan-Downloader.Win32.Tovkater.pwx
NANO-AntivirusTrojan.Win32.InstallMonster.euoyxd
TencentWin32.Trojan-downloader.Tovkater.Eanl
Ad-AwareGen:Variant.Ursu.12444
EmsisoftGen:Variant.Ursu.12444 (B)
ComodoTrojWare.Win32.TrojanDownloader.Tovkater.DF@7e42g4
F-SecureAdware.ADWARE/InstMonster.Gen7
DrWebTrojan.InstallMonster.2404
ZillyaDownloader.Tovkater.Win32.538
TrendMicroPossible_HPGen-32
McAfee-GW-EditionBehavesLike.Win32.Downloader.cc
SophosMal/Generic-S
IkarusTrojan-Downloader.Win32.Tovkater
AviraHEUR/AGEN.1117983
MAXmalware (ai score=96)
Antiy-AVLTrojan/Win32.TSGeneric
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.Ursu.D309C
ZoneAlarmTrojan-Downloader.Win32.Tovkater.pwx
GDataGen:Variant.Ursu.12444
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Tovkater.174471
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34804.mC0@a4PFtgoG
ALYacGen:Variant.Ursu.12444
VBA32TrojanDownloader.Tovkater
MalwarebytesGeneric.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
ESET-NOD32Win32/TrojanDownloader.Tovkater.FU
TrendMicro-HouseCallPossible_HPGen-32
RisingMalware.Obscure/Heur!1.9E03 (CLASSIC)
YandexTrojan.DL.Tovkater!kbJ4U9X/Jd4
SentinelOneStatic AI – Suspicious PE – Downloader
eGambitUnsafe.AI_Score_99%
FortinetW32/Tovkater.FQ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Ursu.12444?

Ursu.12444 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment