Malware

Ursu.19244 removal guide

Malware Removal

The Ursu.19244 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.19244 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Anomalous binary characteristics

How to determine Ursu.19244?


File Info:

crc32: CF244E57
md5: b62e4524282c15dedad9b4d2e37f0830
name: B62E4524282C15DEDAD9B4D2E37F0830.mlw
sha1: f304a0f203c37633cdd751a7968705e93ee1f2d7
sha256: 166d4b45b3dec635fff3fb6e6af76e3eadecd4356e5479a4a19f8c4be6ef30aa
sha512: 6c0c60b8d841a9f0346b1818b1a6b201e0be331246beddf658e58261dfed68ab3f5e59471d0815bf9296750e90ae4bc205e86ad5519a91571c7d10cae90cd4f8
ssdeep: 3072:8QkXX7x1PSOcXdkgYe4dKdBW36yDFPxKqUqrtcrQquoQoO:8r/dcXn4MBWF/UqxiBVM
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (c) Angus Johnson 1999-2002
InternalName: ResHack
FileVersion: 3.4.0.79
CompanyName:
LegalTrademarks:
Comments: Freeware, but see help file for conditions.
ProductName:
ProductVersion: 3.0.0.0
FileDescription: Resource viewer
OriginalFilename: ResHack
Aditional Notes: Not for distribution without the authors permission
Translation: 0x0c09 0x04e4

Ursu.19244 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004f54101 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.4795
MicroWorld-eScanGen:Variant.Ursu.19244
ALYacGen:Variant.Ursu.19244
CylanceUnsafe
ZillyaTrojan.Foreign.Win32.56985
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Foreign.61d22e1e
K7GWTrojan ( 004f54101 )
Cybereasonmalicious.4282c1
CyrenW32/S-2800767d!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.FBOJ
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Foreign.nulp
BitDefenderGen:Variant.Ursu.19244
NANO-AntivirusTrojan.Win32.Kryptik.evimbm
TencentMalware.Win32.Gencirc.10b6e071
Ad-AwareGen:Variant.Ursu.19244
SophosML/PE-A + Mal/Ransom-EE
ComodoTrojWare.Win32.Zbot.EZXT@7tgdwr
BitDefenderThetaGen:NN.ZexaF.34628.ju1@aeIU2Ldi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Foreign.R002C0PBB21
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.b62e4524282c15de
EmsisoftGen:Variant.Ursu.19244 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftPWS:Win32/Zbot
AegisLabTrojan.Win32.Foreign.j!c
GDataGen:Variant.Ursu.19244
Acronissuspicious
McAfeeGenericRXCD-UZ!B62E4524282C
MAXmalware (ai score=99)
VBA32TrojanRansom.Foreign
MalwarebytesZbot.Trojan.Stealer.DDS
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_Foreign.R002C0PBB21
RisingRansom.Foreign!8.292 (CLOUD)
YandexTrojan.GenAsa!zeiOWONvNtM
IkarusTrojan-Spy.Agent
FortinetW32/Kryptik.EZAD!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.Zbot.J

How to remove Ursu.19244?

Ursu.19244 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment