Malware

Ursu.45244 removal tips

Malware Removal

The Ursu.45244 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ursu.45244 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Expresses interest in specific running processes
  • A process created a hidden window
  • Performs some HTTP requests
  • Executed a process and injected code into it, probably while unpacking
  • Queries information on disks for anti-virtualization via Device Information APIs
  • Code injection with CreateRemoteThread in a remote process
  • A process attempted to delay the analysis task by a long amount of time.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

edgedl.me.gvt1.com

How to determine Ursu.45244?


File Info:

crc32: 12FB6777
md5: b0ed157e955a9d99d9506ba506d7b3e5
name: B0ED157E955A9D99D9506BA506D7B3E5.mlw
sha1: 9a0a93c0896684a4847829bafaf6b9fb3c2bb802
sha256: 0185bb02e409f9eca3add5b013b0b94abd20baaac77e2b896b3991b56926d836
sha512: 202cdb0a85f49a465c0df24a212964aaaa9a6c3efb3adc78f85972a9f75c6197f74795767f0f709d9d6847c4fd6a4d1127f3722bd8263d5ba9c3eed821029997
ssdeep: 3072:hKLgUl52ObRdGPwqBNjXnAg0FuekstIhDNgtiuMDU3LyHY4t65uH+SIRmJSyFReD:hsF5nbzI5nAOT9L3U3oYo65unFJSGiv
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ursu.45244 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.11532
ClamAVWin.Packed.Zusy-7057617-0
CAT-QuickHealBackdoor.Androm.A5
ALYacGen:Variant.Ursu.45244
CylanceUnsafe
ZillyaBackdoor.Androm.Win32.42466
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0050b3ad1 )
K7AntiVirusTrojan ( 0050b3ad1 )
CyrenW32/S-1506d0a5!Eldorado
ESET-NOD32a variant of Win32/Kryptik.FRCS
APEXMalicious
AvastWin32:Bzofiku-A [Drp]
CynetMalicious (score: 100)
KasperskyWorm.Win32.Oxynoxy.xu
BitDefenderGen:Variant.Ursu.45244
NANO-AntivirusTrojan.Win32.Androm.enqukw
ViRobotTrojan.Win32.XPacker.Gen
MicroWorld-eScanGen:Variant.Ursu.45244
TencentMalware.Win32.Gencirc.10b44ed1
Ad-AwareGen:Variant.Ursu.45244
SophosMal/Generic-S
ComodoTrojWare.Win32.Lethic.M@6wt8pn
BitDefenderThetaAI:Packer.419F4C421F
TrendMicroTROJ_KRYPTIK_GD170080.UVPM
McAfee-GW-EditionBehavesLike.Win32.Trojan.fh
FireEyeGeneric.mg.b0ed157e955a9d99
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Androm.opw
AviraHEUR/AGEN.1103301
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Ursu.DB0BC
SUPERAntiSpywareBackdoor.Andromeda/Variant
ZoneAlarmWorm.Win32.Oxynoxy.xu
GDataGen:Variant.Ursu.45244
AhnLab-V3Trojan/Win32.Androm.R198422
Acronissuspicious
McAfeeTrojan-FMLV!B0ED157E955A
MAXmalware (ai score=84)
VBA32BScope.Worm.Oxynoxy
MalwarebytesBackdoor.Bot
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_KRYPTIK_GD170080.UVPM
RisingTrojan.Kryptik!1.AA6E (CLASSIC)
YandexTrojan.GenAsa!bMf6sIsDZnw
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.FRAS!tr
AVGWin32:Bzofiku-A [Drp]

How to remove Ursu.45244?

Ursu.45244 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment