Malware

About “Ursu.444204” infection

Malware Removal

The Ursu.444204 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.444204 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ursu.444204?


File Info:

crc32: 4ADC2E9E
md5: 9fccf8596457cbea3050aa45a92a4911
name: file_save.exe
sha1: f2e9614af7ef9dbee19f9695fbcd055463478026
sha256: b5679e6cdaeb67738ea6426fe4c779adfbdfe05109fdb24f92c0041fed3755e2
sha512: 19a0016f285508aaaa40f1b00fa2cb8e20750172e945c574213388501f1fc6f295b021fb1d4bae856e7f78b1510e5e556d4b8f2ade1115a3bb1e2cef13937eec
ssdeep: 196608:fA5AXAs/dn8PTKpQe3wa69uCumymcKTW:XXAs/dIoQeZ69BFRcB
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

ProductVersion: 1.0.0.0
ProductName: File Save
FileVersion: 1.0.0.0
CompanyName: File Save
Translation: 0x0409 0x04e4

Ursu.444204 also known as:

MicroWorld-eScanGen:Variant.Ursu.444204
FireEyeGeneric.mg.9fccf8596457cbea
McAfeeArtemis!9FCCF8596457
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 004046cf1 )
BitDefenderGen:Variant.Ursu.444204
K7GWTrojan ( 004046cf1 )
Cybereasonmalicious.96457c
Invinceaheuristic
BaiduWin32.Packed.VMProtect.a
SymantecML.Attribute.HighConfidence
APEXMalicious
GDataGen:Variant.Ursu.444204
Kasperskynot-a-virus:AdWare.Win32.InstallDisck.c
AlibabaAdWare:Win32/InstallDisck.813d0c40
NANO-AntivirusTrojan.Win32.Black.gfpulx
AegisLabTrojan.Win32.Ursu.4!c
RisingTrojan.Generic@ML.95 (RDML:+mRlqTErd438tRJhCyvYkg)
Endgamemalicious (high confidence)
SophosMal/VMProtBad-A
F-SecureTrojan.TR/Black.Gen2
TrendMicroTROJ_GEN.R002C0RK419
McAfee-GW-EditionBehavesLike.Win32.Dropper.wc
EmsisoftGen:Variant.Ursu.444204 (B)
IkarusTrojan.Win32.VMProtect
CyrenW32/Trojan.VHKO-1442
AviraTR/Black.Gen2
MAXmalware (ai score=83)
MicrosoftTrojan:Win32/Occamy.C
ArcabitTrojan.Ursu.D6C72C
ZoneAlarmnot-a-virus:AdWare.Win32.InstallDisck.c
ALYacGen:Variant.Ursu.444204
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Packed.VMProtect.ABD
TrendMicro-HouseCallTROJ_GEN.R002C0RK419
SentinelOneDFI – Malicious PE
FortinetAdware/InstallDisck
Ad-AwareGen:Variant.Ursu.444204
AVGFileRepMalware
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.17b

How to remove Ursu.444204?

Ursu.444204 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment