Malware

Should I remove “Ursu.32449”?

Malware Removal

The Ursu.32449 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.32449 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Sniffs keystrokes
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

Related domains:

aol.com
mail.sdjosierjoiejfc.com
apple.i-tunes.download

How to determine Ursu.32449?


File Info:

crc32: 50C54682
md5: 46954b97ebfb252c1a7876bdd7dce811
name: 46954B97EBFB252C1A7876BDD7DCE811.mlw
sha1: 3a1fb4e7dcec0e4072cb4595202b034e654a5f2e
sha256: f896d3b6469578727929732761cce18a3534b9842ab1f504c1372968fa6d6faf
sha512: 64264b1dbc3c083bde5a7978a0d2527245b4db4b5c76b69835cad746d1c419ca2c52344d79c07ff9be165e0cdaa3389ca82f90a0860c40917f74f9bcc10e3747
ssdeep: 6144:SMJzDfVDH+sf6qzkyLZF1O2EZLvExxjcixs+XNhkA6GSaRXfy1n2e:vDfpH+sfnz1Lj1OZZs4ixsiNhkApRa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 2005-2017 TC & Co
InternalName: TCstatus
FileVersion: 5.0.2.4
CompanyName: TC & Co
LegalTrademarks: TC & Co
Comments: TCstatus
ProductName: TCstatus v5.0
ProductVersion: 5.0.2.4
FileDescription: TC status
OriginalFilename: TCstatus.exe
Translation: 0x0409 0x04e4

Ursu.32449 also known as:

K7AntiVirusTrojan ( 7000000f1 )
LionicTrojan.Win32.Blocker.tqvm
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader14.35508
CynetMalicious (score: 100)
ALYacGen:Variant.Ursu.32449
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.39516
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/Blocker.123f2809
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.7ebfb2
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/PSW.Delf.ORL
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Blocker.klsu
BitDefenderGen:Variant.Ursu.32449
NANO-AntivirusTrojan.Win32.Blocker.evekkx
MicroWorld-eScanGen:Variant.Ursu.32449
TencentMalware.Win32.Gencirc.11495444
Ad-AwareGen:Variant.Ursu.32449
SophosMal/Generic-S
ComodoMalware@#1zkie79rkg7x6
BitDefenderThetaAI:Packer.0465D07E16
VIPRETrojan.Win32.Generic.pak!cobra
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
FireEyeGeneric.mg.46954b97ebfb252c
EmsisoftGen:Variant.Ursu.32449 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/Generic.bfgib
AviraTR/Crypt.ZPACK.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.240F951
MicrosoftPWS:Win32/Zbot!ml
GDataGen:Variant.Ursu.32449
AhnLab-V3Trojan/Win32.Blocker.C2273292
McAfeeGenericRXDH-AG!46954B97EBFB
MAXmalware (ai score=98)
VBA32Trojan-Ransom.Blocker
MalwarebytesMalware.AI.1466725513
PandaTrj/GdSda.A
YandexTrojan.GenAsa!EiI03eFRHU0
IkarusTrojan.Win32.Virtumonde
FortinetW32/Blocker.KLSU!tr
AVGWin32:Malware-gen

How to remove Ursu.32449?

Ursu.32449 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment